CVE-2026-84121
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefo
CVSS
9.6
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 1 sept 2026 · Última mod.: 1 sept 2026 · CWE-416
Sin historial EPSS suficiente todavía.
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2059018
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-82/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-83/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-84/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-85/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-86/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-87/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-88/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-84353——
———Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)3hCVE-2026-84352——
———Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)3hCVE-2026-84350——
———Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)3hCVE-2026-84349——
———Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)3hCVE-2026-84347——
———Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)3hCVE-2026-84333——
———Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)3h