CVE-2026-84125
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-84125 is a use-after-free vulnerability in the DOM: Core & HTML component of Mozilla Firefox, reported by security researcher Yaqoub Aldurayhim. It affects Firefox versions prior to 155 and Firefox ESR versions prior to 153.2. The vulnerability was disclosed and patched on September 1, 2026, as part of Mozilla Foundation Security Advisories MFSA2026-82 and MFSA2026-85. It carries a CVSS v3.1 base score of 5.4 (Medium), though Mozilla rates its impact as High (Mozilla Advisory ESR, Mozilla Advisory FF155).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), occurring within Firefox's DOM: Core & HTML component. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to influence the contents of that memory and redirect program execution. Exploitation requires user interaction — typically luring a victim to visit a malicious web page — and no special privileges are needed on the part of the attacker. The underlying bug is tracked as Mozilla Bug 2063871, though the bug report is access-restricted (Mozilla Advisory ESR, Mozilla Advisory FF155).

Impact

Successful exploitation could allow a remote attacker to achieve limited confidentiality and integrity impacts within the context of the browser process, consistent with the CVSS assessment of low confidentiality and low integrity impact with no availability impact. In practice, use-after-free vulnerabilities in browser DOM components can potentially be leveraged for memory corruption, information disclosure, or as a stepping stone toward more severe exploitation such as code execution, depending on heap layout and additional primitives. The scope is limited to the affected browser instance and does not directly affect the underlying operating system without chaining with additional vulnerabilities (Mozilla Advisory ESR, Mozilla Advisory FF155).

Exploitability

As of the disclosure date, there is no public evidence of active in-the-wild exploitation or publicly available proof-of-concept exploit code for CVE-2026-84125. The NVD SSVC assessment indicates exploitation is rated as "none" and the vulnerability is not automatable, requiring user interaction. The EPSS score is reported as 0.0, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (Mozilla Advisory ESR, Mozilla Advisory FF155).

Mitigation and workarounds

Mozilla has released patches addressing CVE-2026-84125 in Firefox 155 and Firefox ESR 153.2, both announced on September 1, 2026. Users and administrators should update Firefox to version 155 or later, or Firefox ESR to version 153.2 or later, as soon as possible. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Mozilla Advisory FF155, Mozilla Advisory ESR).

Community reactions

The vulnerability was noted in standard security aggregation feeds and vulnerability databases shortly after disclosure, including VulDB and CVEFeed. No notable independent researcher commentary, significant media coverage, or unusual community reaction has been identified beyond routine tracking of the Mozilla September 2026 security advisory cycle.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84121CRITICAL9.6
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesSep 01, 2026
CVE-2026-84123HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84125MEDIUM5.4
  • NixOS logoNixOS
  • mozjs38
NoYesSep 01, 2026
CVE-2026-84124MEDIUM5.4
  • NixOS logoNixOS
  • firefox
NoYesSep 01, 2026
CVE-2026-84122MEDIUM5.4
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management