Sandbox Escape Vulnerability in Firefox Navigational Component
CVE-2026-84119

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84119?

A vulnerability has been identified in Firefox's navigation component that enables a sandbox escape due to a use-after-free condition. When navigating the DOM, improper handling of memory can lead to unexpected behavior, potentially allowing attackers to execute arbitrary code. This issue was resolved in multiple updates across Firefox and Firefox ESR versions. Users are advised to upgrade to the latest versions to mitigate any risks associated with this vulnerability.

Affected Version(s)

Firefox 115.40

Firefox 140.15

Firefox 153.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaqoub Aldurayhim
.