CVE-2026-8969
DOM Security Component Mitigation Bypass in Firefox
Publication date: 2026-05-19
Last updated on: 2026-05-20
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | to 151.0.0 (exc) |
| mozilla | thunderbird | to 151.0.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a mitigation bypass in the DOM (Document Object Model) security component of Mozilla Firefox. It means that a security measure intended to protect the DOM was circumvented, potentially allowing an attacker to exploit the browser in ways that were previously prevented. The issue was fixed in Firefox version 151.
How can this vulnerability impact me? :
By bypassing the DOM security mitigation, an attacker could potentially manipulate web content or execute unauthorized actions within the browser environment. This could lead to security risks such as unauthorized data access, execution of malicious scripts, or other browser-based attacks.
What immediate steps should I take to mitigate this vulnerability?
The vulnerability was fixed in Firefox 151. The immediate step to mitigate this vulnerability is to update your Firefox browser to version 151 or later.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability is a mitigation bypass in the DOM security component with a high CVSS score indicating high impact on confidentiality and integrity. Such vulnerabilities can potentially lead to unauthorized access to sensitive data, which may affect compliance with data protection regulations like GDPR and HIPAA that require safeguarding personal and sensitive information.
However, the provided information does not explicitly describe the direct impact on compliance with specific standards or regulations.