SB2026090144 - Multiple vulnerabilities in Mozilla Firefox



SB2026090144 - Multiple vulnerabilities in Mozilla Firefox

Published: September 1, 2026

Security Bulletin ID SB2026090144
CSH Severity
High
Patch available
YES
Number of vulnerabilities 29
Exploitation vector Remote access
Highest impact Privilege escalation

Breakdown by Severity

High 45% Medium 17% Low 38%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 29 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-84128)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in the WebDriver BiDi component when handling protocol functionality. A remote user can perform crafted protocol actions to escalate privileges.


2) Input validation error (CVE-ID: CVE-2026-84134)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an unspecified error in the profile backup component. A remote attacker can bypass implemented security restrictions. 


3) Input validation error (CVE-ID: CVE-2026-84135)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an unspecified error. A remote attacker can bypass implemented security restrictions. 


4) Input validation error (CVE-ID: CVE-2026-84136)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an unspecified error in the DOM navigation component. A remote attacker can bypass implemented security restrictions. 


5) Buffer overflow (CVE-ID: CVE-2026-84143)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger a security-relevant defect to execute arbitrary code.

The advisory describes multiple internally found bugs, some of which showed evidence of memory corruption or another security-relevant defect.


6) Use-after-free (CVE-ID: CVE-2026-84118)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the JavaScript: GC component when processing crafted web content. A remote attacker can trigger garbage collection with crafted content to execute arbitrary code.

User interaction is required to visit a crafted website or URL.


7) Use-after-free (CVE-ID: CVE-2026-84119)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in DOM: Navigation component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.

User interaction is required.


8) Use-after-free (CVE-ID: CVE-2026-84120)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in Audio/Video component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to execute arbitrary code.

User interaction is required.


9) Use-after-free (CVE-ID: CVE-2026-84121)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in DOM: Security component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.

User interaction is required.


10) Use-after-free (CVE-ID: CVE-2026-84122)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Audio/Video component when processing crafted media content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


11) Use-after-free (CVE-ID: CVE-2026-84123)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to use-after-free in the Graphics: WebGPU component when processing crafted web content. A remote attacker can trigger the vulnerable condition to escalate privileges.

User interaction is required to visit a crafted website or URL.


12) Use-after-free (CVE-ID: CVE-2026-84124)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


13) Use-after-free (CVE-ID: CVE-2026-84125)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can trigger the vulnerable condition to execute arbitrary code.

User interaction is required to visit a crafted website or URL.


14) Input validation error (CVE-ID: CVE-2026-84126)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in the Layout: Grid component when rendering crafted web content. A remote attacker can supply content that triggers incorrect boundary conditions to execute arbitrary code.


15) Information disclosure (CVE-ID: CVE-2026-84127)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the WebExtensions component when interacting with extension functionality. A remote user can access exposed information to disclose sensitive information.


16) Information disclosure (CVE-ID: CVE-2026-84132)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper information exposure in the Networking: HTTP component when handling crafted web requests. A remote attacker can trigger the vulnerable behavior to disclose sensitive information.

User interaction is required to visit a crafted website or URL.


17) Protection mechanism failure (CVE-ID: CVE-2026-84129)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass site isolation restrictions.

The vulnerability exists due to improper isolation in the DOM: Navigation component when handling crafted web navigation. A remote attacker can trigger crafted navigation to bypass site isolation restrictions.

User interaction is required to visit a crafted website or URL.


18) Information disclosure (CVE-ID: CVE-2026-84130)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the Graphics: WebGPU component when processing crafted web content. A remote attacker can trigger the vulnerable behavior to disclose sensitive information.

User interaction is required to visit a crafted website or URL.


19) NULL pointer dereference (CVE-ID: CVE-2026-84131)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to invalid pointer dereference in Graphics component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escalate privileges.

User interaction is required.


20) Protection mechanism failure (CVE-ID: CVE-2026-84133)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass site isolation restrictions.

The vulnerability exists due to improper isolation in the DOM: Push Subscriptions component when handling crafted web content. A remote attacker can trigger the vulnerable behavior to bypass site isolation restrictions.

User interaction is required to visit a crafted website or URL.


21) Improper access control (CVE-ID: CVE-2026-84117)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in Firefox for Android when handling application functionality. A remote user can perform crafted actions within the application to escalate privileges.


22) Buffer overflow (CVE-ID: CVE-2026-84145)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing web content. A remote attacker can convince the victim to visit a specially crafted website to cause a denial of service or execute arbitrary code.

The issue covers multiple internally found bugs.


23) Origin validation error (CVE-ID: CVE-2026-84137)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to spoof content.

The vulnerability exists due to improper origin validation in the DOM: Core & HTML component when rendering crafted web content. A remote attacker can present crafted content to spoof content.

User interaction is required to visit a crafted website or URL.


24) Input validation error (CVE-ID: CVE-2026-84138)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the PDF Viewer component when rendering a crafted PDF document. A remote attacker can supply a crafted PDF document to cause a denial of service.

User interaction is required to open a crafted PDF document.


25) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-84139)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform clickjacking attacks.

The vulnerability exists due to improper UI protection in the DOM: Events component when rendering crafted web content. A remote attacker can present crafted content to perform clickjacking attacks.

User interaction is required to interact with crafted content.


26) Protection mechanism failure (CVE-ID: CVE-2026-84140)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass site isolation restrictions.

The vulnerability exists due to improper isolation in the DOM: Navigation component when handling crafted web navigation. A remote attacker can trigger crafted navigation to bypass site isolation restrictions.

User interaction is required to visit a crafted website or URL.


27) Integer overflow (CVE-ID: CVE-2026-84141)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Graphics: ImageLib component when parsing crafted image content. A remote attacker can supply crafted image content to cause a denial of service.

User interaction is required to visit a crafted website or URL.


28) Buffer overflow (CVE-ID: CVE-2026-84142)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to affect security in an unspecified manner.

The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing crafted input. A remote attacker can trigger the underlying flaw to affect security in an unspecified manner.

The advisory describes multiple internally found bugs rather than a single fully characterized flaw.


29) Buffer overflow (CVE-ID: CVE-2026-84144)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger the vulnerable behavior to execute arbitrary code.

The advisory states that some internally found bugs showed evidence of memory corruption or another security-relevant defect.


Remediation

Install update from vendor's website.

References