
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-84125 is a use-after-free vulnerability in the DOM: Core & HTML component of Mozilla Firefox, reported by security researcher Yaqoub Aldurayhim. It affects Firefox versions prior to 155 and Firefox ESR versions prior to 153.2. The vulnerability was disclosed and patched on September 1, 2026, as part of Mozilla Foundation Security Advisories MFSA2026-82 and MFSA2026-85. It carries a CVSS v3.1 base score of 5.4 (Medium), though Mozilla rates its impact as High (Mozilla Advisory ESR, Mozilla Advisory FF155).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), occurring within Firefox's DOM: Core & HTML component. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to influence the contents of that memory and redirect program execution. Exploitation requires user interaction — typically luring a victim to visit a malicious web page — and no special privileges are needed on the part of the attacker. The underlying bug is tracked as Mozilla Bug 2063871, though the bug report is access-restricted (Mozilla Advisory ESR, Mozilla Advisory FF155).
Successful exploitation could allow a remote attacker to achieve limited confidentiality and integrity impacts within the context of the browser process, consistent with the CVSS assessment of low confidentiality and low integrity impact with no availability impact. In practice, use-after-free vulnerabilities in browser DOM components can potentially be leveraged for memory corruption, information disclosure, or as a stepping stone toward more severe exploitation such as code execution, depending on heap layout and additional primitives. The scope is limited to the affected browser instance and does not directly affect the underlying operating system without chaining with additional vulnerabilities (Mozilla Advisory ESR, Mozilla Advisory FF155).
As of the disclosure date, there is no public evidence of active in-the-wild exploitation or publicly available proof-of-concept exploit code for CVE-2026-84125. The NVD SSVC assessment indicates exploitation is rated as "none" and the vulnerability is not automatable, requiring user interaction. The EPSS score is reported as 0.0, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported (Mozilla Advisory ESR, Mozilla Advisory FF155).
Mozilla has released patches addressing CVE-2026-84125 in Firefox 155 and Firefox ESR 153.2, both announced on September 1, 2026. Users and administrators should update Firefox to version 155 or later, or Firefox ESR to version 153.2 or later, as soon as possible. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Mozilla Advisory FF155, Mozilla Advisory ESR).
The vulnerability was noted in standard security aggregation feeds and vulnerability databases shortly after disclosure, including VulDB and CVEFeed. No notable independent researcher commentary, significant media coverage, or unusual community reaction has been identified beyond routine tracking of the Mozilla September 2026 security advisory cycle.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."