External risk intelligence

Mozilla Firefox and Thunderbird Site Isolation DOM Push Subscriptions Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84133

This vulnerability affects web browser and email client software, which are client-side applications. It requires a user to navigate to a malicious site or interact with content within the application. It is not an internet-facing service, gateway, or appliance that is reachable or listening for incoming connections from the public internet by design.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A site isolation issue was discovered in the DOM: Push Subscriptions component, impacting Mozilla Firefox and Thunderbird. This vulnerability, rated critical, could potentially allow for significant compromise of confidentiality, integrity, and availability. The main concern at this stage is confirming relevance and exposure to our environments.

  • An issue exists in web browser and email software.
  • Critical vulnerability could impact confidentiality and integrity.
  • Confirm relevance and exposure to our environments.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking a user into visiting a malicious website or opening a specially crafted email. This would allow them to interact with the vulnerable component, potentially leading to the compromise of the user's session data and other sensitive information.

  • No authentication required.
  • User interaction triggers vulnerability.
  • Leads to data compromise.

Live Threat

Current exploitation, exposure, and threat context

A site isolation issue within the DOM: Push Subscriptions component could allow an attacker to affect service behavior or access sensitive information when supported by the advisory.

  • Browser and email client data at risk.
  • Malicious content or sites could trigger exposure.
  • Compromised service behavior or information access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This site isolation vulnerability in Mozilla's Firefox and Thunderbird products requires a user to interact with malicious content. Owners of endpoint devices and application support teams should prioritize identifying all instances of affected software across their environment. The immediate next step is to confirm exposure for business-critical systems and then schedule updates during planned maintenance windows, coordinating with any relevant vendor management processes.

  • Endpoint and application owners should address this.
  • Verify user exposure and critical system impact.
  • Plan and execute necessary updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Push Subscriptions component in Firefox and Thunderbird?

This component manages how web applications send real-time notifications to your browser or email client, even when the site isn't actively open. It handles the secure delivery of these messages by keeping track of authorized channels. Because it bridges external content and your local software, it is a critical gatekeeper for maintaining site isolation, ensuring that one website cannot improperly access or influence data belonging to another.

How does CVE-2026-84133 work as a site isolation vulnerability?

This flaw is classified under CWE-346, which involves issues with how an application verifies the origin of data. In this specific case, the Push Subscriptions component fails to properly enforce boundaries, allowing unauthorized content to bypass security restrictions. Essentially, the software loses track of which site is allowed to communicate with certain internal functions, potentially letting malicious code act as if it were a trusted origin.

Do I need to be logged into a specific site to trigger this bug?

No, authentication is not required for an attacker to leverage this issue. The vulnerability is triggered by user interaction, such as simply visiting a malicious website or opening a specially crafted email containing the necessary triggers. If you do not interact with malicious content or navigate to untrusted sites, the vulnerability generally remains dormant and is not triggered by background browser processes alone.

Is this CVE a risk if my machine is not directly internet-facing?

Halo Surface Signal notes that this is a client-side vulnerability rather than a server-side gateway or appliance issue. While your machine might not be an internet-facing server, you are still exposed if the software is used to browse the web or access email. The risk depends on your active usage of the browser or email client to interact with external content, as the threat relies on the user encountering malicious material.

When should I update my Firefox or Thunderbird installation?

You should prioritize updating as soon as your standard maintenance window allows. Because this vulnerability carries a critical severity rating, identifying all instances of Firefox or Thunderbird across your environment is the recommended first step. Once you confirm where the affected versions are running, coordinate with your technical teams to apply the vendor-provided patches that resolve the site isolation failure.

References