SB2026090144 - Multiple vulnerabilities in Mozilla Firefox
Published: September 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 29 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-84128)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in the WebDriver BiDi component when handling protocol functionality. A remote user can perform crafted protocol actions to escalate privileges.
2) Input validation error (CVE-ID: CVE-2026-84134)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error in the profile backup component. A remote attacker can bypass implemented security restrictions.
3) Input validation error (CVE-ID: CVE-2026-84135)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error. A remote attacker can bypass implemented security restrictions.
4) Input validation error (CVE-ID: CVE-2026-84136)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error in the DOM navigation component. A remote attacker can bypass implemented security restrictions.
5) Buffer overflow (CVE-ID: CVE-2026-84143)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger a security-relevant defect to execute arbitrary code.
The advisory describes multiple internally found bugs, some of which showed evidence of memory corruption or another security-relevant defect.
6) Use-after-free (CVE-ID: CVE-2026-84118)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript: GC component when processing crafted web content. A remote attacker can trigger garbage collection with crafted content to execute arbitrary code.
User interaction is required to visit a crafted website or URL.
7) Use-after-free (CVE-ID: CVE-2026-84119)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in DOM: Navigation component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.
User interaction is required.
8) Use-after-free (CVE-ID: CVE-2026-84120)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Audio/Video component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to execute arbitrary code.
User interaction is required.
9) Use-after-free (CVE-ID: CVE-2026-84121)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in DOM: Security component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.
User interaction is required.
10) Use-after-free (CVE-ID: CVE-2026-84122)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Audio/Video component when processing crafted media content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
11) Use-after-free (CVE-ID: CVE-2026-84123)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use-after-free in the Graphics: WebGPU component when processing crafted web content. A remote attacker can trigger the vulnerable condition to escalate privileges.
User interaction is required to visit a crafted website or URL.
12) Use-after-free (CVE-ID: CVE-2026-84124)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
13) Use-after-free (CVE-ID: CVE-2026-84125)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can trigger the vulnerable condition to execute arbitrary code.
User interaction is required to visit a crafted website or URL.
14) Input validation error (CVE-ID: CVE-2026-84126)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in the Layout: Grid component when rendering crafted web content. A remote attacker can supply content that triggers incorrect boundary conditions to execute arbitrary code.
15) Information disclosure (CVE-ID: CVE-2026-84127)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the WebExtensions component when interacting with extension functionality. A remote user can access exposed information to disclose sensitive information.
16) Information disclosure (CVE-ID: CVE-2026-84132)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper information exposure in the Networking: HTTP component when handling crafted web requests. A remote attacker can trigger the vulnerable behavior to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
17) Protection mechanism failure (CVE-ID: CVE-2026-84129)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper isolation in the DOM: Navigation component when handling crafted web navigation. A remote attacker can trigger crafted navigation to bypass site isolation restrictions.
User interaction is required to visit a crafted website or URL.
18) Information disclosure (CVE-ID: CVE-2026-84130)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics: WebGPU component when processing crafted web content. A remote attacker can trigger the vulnerable behavior to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
19) NULL pointer dereference (CVE-ID: CVE-2026-84131)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to invalid pointer dereference in Graphics component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escalate privileges.
User interaction is required.
20) Protection mechanism failure (CVE-ID: CVE-2026-84133)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper isolation in the DOM: Push Subscriptions component when handling crafted web content. A remote attacker can trigger the vulnerable behavior to bypass site isolation restrictions.
User interaction is required to visit a crafted website or URL.
21) Improper access control (CVE-ID: CVE-2026-84117)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in Firefox for Android when handling application functionality. A remote user can perform crafted actions within the application to escalate privileges.
22) Buffer overflow (CVE-ID: CVE-2026-84145)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing web content. A remote attacker can convince the victim to visit a specially crafted website to cause a denial of service or execute arbitrary code.
The issue covers multiple internally found bugs.
23) Origin validation error (CVE-ID: CVE-2026-84137)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof content.
The vulnerability exists due to improper origin validation in the DOM: Core & HTML component when rendering crafted web content. A remote attacker can present crafted content to spoof content.
User interaction is required to visit a crafted website or URL.
24) Input validation error (CVE-ID: CVE-2026-84138)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the PDF Viewer component when rendering a crafted PDF document. A remote attacker can supply a crafted PDF document to cause a denial of service.
User interaction is required to open a crafted PDF document.
25) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-84139)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking attacks.
The vulnerability exists due to improper UI protection in the DOM: Events component when rendering crafted web content. A remote attacker can present crafted content to perform clickjacking attacks.
User interaction is required to interact with crafted content.
26) Protection mechanism failure (CVE-ID: CVE-2026-84140)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper isolation in the DOM: Navigation component when handling crafted web navigation. A remote attacker can trigger crafted navigation to bypass site isolation restrictions.
User interaction is required to visit a crafted website or URL.
27) Integer overflow (CVE-ID: CVE-2026-84141)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics: ImageLib component when parsing crafted image content. A remote attacker can supply crafted image content to cause a denial of service.
User interaction is required to visit a crafted website or URL.
28) Buffer overflow (CVE-ID: CVE-2026-84142)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to affect security in an unspecified manner.
The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing crafted input. A remote attacker can trigger the underlying flaw to affect security in an unspecified manner.
The advisory describes multiple internally found bugs rather than a single fully characterized flaw.
29) Buffer overflow (CVE-ID: CVE-2026-84144)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger the vulnerable behavior to execute arbitrary code.
The advisory states that some internally found bugs showed evidence of memory corruption or another security-relevant defect.
Remediation
Install update from vendor's website.
References
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2044280
- https://bugzilla.mozilla.org/show_bug.cgi?id=2044882
- https://bugzilla.mozilla.org/show_bug.cgi?id=2048699
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048793%2C2054645%2C2057114%2C2059109%2C2061287
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057457
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057817
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058911
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059018
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059965
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060047
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061110
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063871
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063893
- https://bugzilla.mozilla.org/show_bug.cgi?id=1699444
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063020
- https://bugzilla.mozilla.org/show_bug.cgi?id=2055028
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057834
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060008
- https://bugzilla.mozilla.org/show_bug.cgi?id=2032388
- https://bugzilla.mozilla.org/show_bug.cgi?id=2053320
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054640%2C2054650%2C2054652%2C2055693%2C2055705%2C2058051%2C2058652%2C2058660%2C2059027%2C2061220%2C2061242%2C2061285%2C2061300%2C2061316%2C2061397
- https://bugzilla.mozilla.org/show_bug.cgi?id=2051146
- https://bugzilla.mozilla.org/show_bug.cgi?id=2056164
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060153
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063780
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063994
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029421%2C2040889%2C2045313%2C2045435%2C2053578%2C2058621%2C2058626
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054625%2C2059002%2C2061775