Mozilla Firefox & Thunderbird: 25 Vulnerabilities Including Critical Sandbox Escapes Disclosed Together
Mozilla Corporation disclosed 25 vulnerabilities in Firefox and Thunderbird on September 1, 2026, including critical sandbox escapes and privilege escalation flaws.

Key findings
- Mozilla disclosed 25 vulnerabilities affecting Firefox and Thunderbird on September 1, 2026.
- Two critical sandbox escape vulnerabilities (CVE-2026-84121, CVE-2026-84119) were among the disclosed flaws.
- Multiple use-after-free and privilege escalation issues were present across various components.
- Patches are available in Firefox 155 and relevant Thunderbird versions.
- The batch includes critical, high, and medium severity vulnerabilities.
On September 1, 2026, Mozilla Corporation disclosed a significant batch of 25 vulnerabilities affecting its Firefox browser and Thunderbird email client. The vulnerabilities, disclosed within a narrow time window, span a range of severity, including critical sandbox escape flaws. These issues highlight potential risks for users who handle various types of content within these applications.
The disclosed vulnerabilities can be broadly categorized by their impact and affected components. Several critical and high-severity flaws were identified, including privilege escalation and memory corruption issues. Specifically, CVE-2026-84121 and CVE-2026-84119 are critical sandbox escape vulnerabilities stemming from use-after-free defects in the DOM: Security and DOM: Navigation components, respectively. Another critical vulnerability, CVE-2026-84129, is a site isolation issue in the DOM: Navigation component. High-severity issues include privilege escalation due to invalid pointer in the Graphics component (CVE-2026-84131) and privilege escalation in the WebDriver BiDi component (CVE-2026-84128).
Memory corruption was a recurring theme, with multiple use-after-free vulnerabilities reported across various components. These include CVE-2026-84125, CVE-2026-84124, CVE-2026-84123, CVE-2026-84120, and CVE-2026-84118, affecting components like DOM: Core & HTML, Audio/Video, and JavaScript: GC. Other vulnerabilities include an integer overflow in the Graphics: ImageLib component (CVE-2026-84141), a clickjacking issue in the DOM: Events component (CVE-2026-84139), and a denial-of-service in the PDF Viewer component (CVE-2026-84138). Information disclosure vulnerabilities were also present, such as CVE-2026-84132 in Networking: HTTP and CVE-2026-84130 in Graphics: WebGPU.
The related news coverage from Vypr Intelligence specifically highlights 16 of these vulnerabilities affecting Thunderbird, noting two critical sandbox escapes (CVE-2026-84121 and CVE-2026-84119) and other privilege escalation and memory corruption themes. While the Vypr report focuses on Thunderbird, the patches mentioned are also relevant to Firefox users, as many of these vulnerabilities were fixed in the same releases.
Mozilla has addressed these vulnerabilities with patches available in Firefox 155, Firefox ESR 153.2, and various Thunderbird versions including 155, 153.2, 140.15, and 115.40. Users are strongly advised to update to the latest versions to protect themselves from potential exploitation. The wide range of vulnerabilities and their critical severity underscore the importance of timely patching for both Firefox and Thunderbird users.
This batch of disclosures serves as a reminder of the ongoing security efforts required to maintain the integrity of widely used software. Users should remain vigilant and apply updates promptly as they become available. The interconnected nature of these disclosures across Firefox and Thunderbird emphasizes the importance of a comprehensive security update strategy for the entire Mozilla ecosystem.