Back to overview

CVE-2026-4689

CRITICAL
10.0
CVSS 3.1
Description
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Metadata

CVE ID
CVE-2026-4689
State
PUBLISHED
Assigner
mozilla
Reserved
2026-03-23 23:21 UTC
Published
2026-03-24 12:30 UTC
Last updated
2026-07-15 00:49 UTC
Primary CWE
CWE-120
CWE-120 Buffer Copy without Checking Size of Input ('Classic…
Vendor / Product
Mozilla / Firefox
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
Mozilla Firefox 115.34 ≤ 115.*, 140.9 ≤ 140.*, 149 ≤ *
Mozilla Thunderbird 140.9 ≤ 140.*, 149 ≤ *
Weakness (CWE)
CWESourceDescription
CWE-120 adp CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CWE-190 adp CWE-190 Integer Overflow or Wraparound
CWE-190 adp Integer Overflow or Wraparound
CVSS scores (2)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
7.5 HIGH 3.1 adp CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Back to overview