Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-84128 represents a privilege escalation vulnerability in the WebDriver BiDi (Bidirectional) component, a standardized protocol for browser automation and testing. WebDriver BiDi is increasingly used in development workflows, CI/CD pipelines, and automated testing frameworks, making this vulnerability particularly concerning. An attacker exploiting this flaw could elevate their privileges from a constrained WebDriver context to gain higher-level access on the affected system. Firefox 155 and Thunderbird 155 users who rely on WebDriver BiDi for legitimate automation or testing purposes face exposure, while defenders must consider how this attack vector could be chained with other techniques to compromise browser-based applications or testing infrastructure.
While no MITRE ATT&CK techniques are currently mapped to this CVE, Casky's security skills powered by Claude AI with extended reasoning capabilities would identify the underlying attack patterns by analyzing behavioral indicators associated with privilege escalation attempts. Practitioners using Casky would observe findings related to suspicious WebDriver BiDi API calls, unexpected process elevation events, and capability changes within browser sandbox environments—key signals that precede successful privilege escalation. By correlating these indicators across the 754 mapped security skills, Casky helps practitioners detect when an attacker attempts to break out of the WebDriver context, enabling rapid response before the vulnerability can be weaponized in real-world attack chains involving lateral movement or persistence mechanisms.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-84128. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation