Site Isolation Vulnerability in Firefox and Firefox ESR
CVE-2026-84133

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84133?

A site isolation vulnerability exists in the Push Subscriptions component of Firefox, allowing potential exposure of user data through improper isolation. This issue has been addressed in Firefox version 155 and Firefox ESR version 153.2. Users are encouraged to update their browsers promptly to maintain security and privacy while browsing.

Affected Version(s)

Firefox 153.2

Firefox 155

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pakhunov.anton.n
.