EXPOSURES › CVE-2026-84141
CVE-2026-84141
CRITICALMozilla Firefox had an integer overflow vulnerability in its ImageLib component that was patched in Firefox 155 and Firefox ESR 153.2.
An integer overflow in Firefox's ImageLib component could theoretically allow remote code execution if exploited, but the source material does not confirm exploitation or RCE. The vulnerability was patched in Firefox 155 and Firefox ESR 153.2. DIB organizations must ensure their browsers are updated to the latest versions to avoid potential exploitation of unpatched vulnerabilities.
Shame score — The vulnerability was patched in a timely manner and was not exploited in the wild, resulting in moderate embarrassment.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.