CVE-2026-84123
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2
CVSS
8.8
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 1, 2026 · Last modified: Sep 1, 2026 · CWE-416
Not enough EPSS history yet.
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2060047
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-82/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-85/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-86/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-88/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-84353——
———Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)3hCVE-2026-84352——
———Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)3hCVE-2026-84350——
———Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)3hCVE-2026-84349——
———Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)3hCVE-2026-84347——
———Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)3hCVE-2026-84333——
———Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)3h