CVE-2026-0879
CRITICAL
9.8
CVSS 3.1
Description
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Mozilla | Firefox | — | 115.32 ≤ 115.*, 140.7 ≤ 140.*, 147 ≤ * |
| Mozilla | Thunderbird | — | 140.7 ≤ 140.*, 147 ≤ * |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-119 | adp | CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | adp | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 7.5 | HIGH | 3.1 | adp | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
References (6)
- https://bugzilla.mozilla.org/show_bug.cgi?id=2004602
- https://www.mozilla.org/security/advisories/mfsa2026-01/
- https://www.mozilla.org/security/advisories/mfsa2026-02/
- https://www.mozilla.org/security/advisories/mfsa2026-03/
- https://www.mozilla.org/security/advisories/mfsa2026-04/
- https://www.mozilla.org/security/advisories/mfsa2026-05/