BlackTree Security · Infrastructure · Automation · AI

Firefox 155 Closed Two Sandbox Escapes, but Six More High-Severity Bugs Came With Them.

Firefox 155 is not a routine browser refresh. Mozilla’s security bulletin lists 29 CVEs, including two high-impact use-after-free vulnerabilities that it explicitly describes as sandbox escapes. The release also fixes several privilege-escalation paths, multiple additional use-after-free bugs, an Android extension data leak and a set of internally discovered defects with signs of memory corruption.

The two sandbox escapes are CVE-2026-84119 in DOM Navigation and CVE-2026-84121 in DOM Security. Mozilla rates both high impact. The bulletin does not say either has been exploited in the wild, and it does not link to a public proof of concept. That distinction matters, but so does the boundary being crossed.

A browser sandbox exists to stop a compromised renderer or hostile web page from gaining broader authority. A flaw that helps code escape that boundary is especially useful when chained with another vulnerability. Firefox users should update to version 155, while organisations on supported ESR branches should also review the separate fixes delivered in ESR 153.2, 140.15 and 115.40.

## Two bugs target the browser’s containment boundary

Mozilla describes both sandbox escapes as use-after-free vulnerabilities. This class of memory-safety error occurs when software continues using memory after it has been released. Under the right conditions, an attacker may be able to turn the resulting corruption into controlled code execution or a change in privileges.

The advisory does not publish exploit mechanics, prerequisites beyond exposure to the affected browser components, or reproduction instructions. That is normal while users are still patching. The practical point is that the vulnerabilities affect the boundary designed to contain hostile content, not merely a low-value interface inside the browser.

Firefox 155 also addresses high-impact privilege escalation on Android and in WebGPU, plus several other use-after-free flaws in JavaScript garbage collection, audio and video handling, and DOM processing. These defects create a broader attack surface than the two headline sandbox escapes alone.

## Every CVE in Mozilla’s Firefox 155 bulletin

Mozilla marks the advisory as high impact and names Firefox 155 as the fixed release. The table below keeps every listed CVE separate. Unless another branch is shown, Mozilla lists Firefox 155 as the fix. The bulletin reports no active exploitation or public proof of concept for any of these issues.

| CVE | Severity | Component and impact | Fixed releases |
|—|—|—|—|
| CVE-2026-84117 | High | Privilege escalation in Firefox for Android | Firefox 155 |
| CVE-2026-84118 | High | Use-after-free in JavaScript garbage collection | Firefox 155 |
| CVE-2026-84119 | High | Sandbox escape caused by use-after-free in DOM Navigation | Firefox 155 |
| CVE-2026-84120 | High | Use-after-free in Audio/Video | Firefox 155 |
| CVE-2026-84121 | High | Sandbox escape caused by use-after-free in DOM Security | Firefox 155 |
| CVE-2026-84122 | High | Use-after-free in Audio/Video | Firefox 155 |
| CVE-2026-84123 | High | WebGPU privilege escalation caused by use-after-free | Firefox 155 |
| CVE-2026-84124 | High | Use-after-free in DOM Core and HTML | Firefox 155 |
| CVE-2026-84125 | High | Use-after-free in DOM Core and HTML | Firefox 155 |
| CVE-2026-84126 | High | Incorrect boundary conditions in Layout Grid | Firefox 155 |
| CVE-2026-84127 | Moderate | Information disclosure through WebExtensions on Android | Firefox 155 |
| CVE-2026-84128 | Moderate | Privilege escalation in WebDriver BiDi | Firefox 155 |
| CVE-2026-84129 | Moderate | Site-isolation failure in DOM Navigation | Firefox 155 |
| CVE-2026-84130 | Moderate | Information disclosure in WebGPU | Firefox 155 |
| CVE-2026-84131 | Moderate | Graphics privilege escalation caused by an invalid pointer | Firefox 155 |
| CVE-2026-84132 | Moderate | Information disclosure in HTTP networking | Firefox 155 |
| CVE-2026-84133 | Low | Site-isolation failure in Push Subscriptions | Firefox 155 |
| CVE-2026-84134 | Low | Security issue in Profile Backup | Firefox 155 |
| CVE-2026-84135 | Low | Security issue in Firefox Focus for Android | Firefox 155 |
| CVE-2026-84136 | Low | Security issue in DOM Navigation | Firefox 155 |
| CVE-2026-84137 | Low | Spoofing in DOM Core and HTML | Firefox 155 |
| CVE-2026-84138 | Low | Denial of service in the PDF viewer | Firefox 155 |
| CVE-2026-84139 | Low | Clickjacking in DOM Events | Firefox 155 |
| CVE-2026-84140 | Low | Site-isolation failure in DOM Navigation | Firefox 155 |
| CVE-2026-84141 | Low | Integer overflow in Graphics ImageLib | Firefox 155 |
| CVE-2026-84142 | Moderate | Internally found security defects, including memory-corruption evidence | Firefox 155 |
| CVE-2026-84143 | High | Internally found defects across current and ESR branches | Firefox 155, ESR 153.2, ESR 140.15 |
| CVE-2026-84144 | High | Internally found defects in current and ESR 153 branches | Firefox 155, ESR 153.2 |
| CVE-2026-84145 | High | Internally found defects across four supported branches | Firefox 155, ESR 153.2, ESR 140.15, ESR 115.40 |

## The memory-safety clusters deserve attention

The bulletin contains five individually identified use-after-free vulnerabilities in addition to the two sandbox escapes, and Mozilla groups further internally discovered defects under four CVE records. For the grouped bugs, Mozilla says some showed evidence of memory corruption or another security-relevant defect and that some could probably have been exploited with enough effort.

That wording is not a claim of exploitation. It is a warning about exploitability. Memory corruption in a browser can provide the first step in a chain, while a sandbox escape supplies the second. Attackers do not need every bug in the bulletin. They need a workable combination that reaches the target platform and version.

## Android and automation environments are also exposed

The update is not only a desktop-browser story. CVE-2026-84117 can elevate privileges in Firefox for Android. CVE-2026-84127 may disclose information through Android WebExtensions, while CVE-2026-84135 affects Firefox Focus for Android.

Teams that use automated testing should also note CVE-2026-84128 in WebDriver BiDi. Browser automation often runs with valuable test credentials and access to development systems. A moderate rating does not remove the need to update those managed images and runners.

## What defenders should do now

– Update standard Firefox installations to version 155.

– Move ESR 153, ESR 140 and ESR 115 deployments to the fixed branch versions that apply to them.

– Verify managed browser policies actually completed the update, rather than checking only that an update was approved.

– Refresh golden images, virtual desktops, browser automation runners and mobile-device baselines.

– Prioritise systems used for web research, privileged administration, development and access to sensitive internal applications.

Mozilla lists no general workaround in the advisory. Restricting untrusted browsing can reduce exposure temporarily, but browser vulnerabilities are commonly triggered through ordinary content-handling paths. Version verification is the reliable control.

## The number is not the story

Twenty-nine CVEs make the release look large, but the count alone does not determine urgency. The more important signal is the mix: two sandbox escapes, several privilege-escalation paths and a dense set of memory-safety defects in a high-reach application.

Firefox is often treated as self-updating consumer software. In an enterprise, it is also an execution environment for untrusted code and a gateway to privileged web applications. The security boundary is only as current as the browser actually running on each endpoint.

## Sources and further reading

– Mozilla Foundation Security Advisory 2026-82, announced 1 September 2026. Mozilla provided no publication time.

– Mozilla Firefox known vulnerabilities.

Leave a Reply

Your email address will not be published. Required fields are marked *