CVE-2026-0879
Critical · CVSS 9.8Mozilla Firefox / Thunderbird — Sandbox escape via incorrect boundary conditions in Graphics component (CWE-119 buffer boundary error)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-119
Description
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
Search profile — drives PoC discovery
Symbols Graphicssandbox escapeboundary conditionsCWE-119mfsa2026-01mfsa2026-02mfsa2026-03mfsa2026-04bug 2004602
Keywords CVE-2026-0879Firefox sandbox escapeFirefox Graphics boundaryThunderbird sandbox escapemfsa2026-01mfsa2026-02Firefox 147 exploitFirefox ESR 115.32Firefox ESR 140.7Thunderbird 147Thunderbird 140.7bugzilla 2004602CWE-119 FirefoxFirefox PoC 2026
Versions: Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, Thunderbird < 140.7
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2004602
- https://www.mozilla.org/security/advisories/mfsa2026-01/
- https://www.mozilla.org/security/advisories/mfsa2026-02/
- https://www.mozilla.org/security/advisories/mfsa2026-03/
- https://www.mozilla.org/security/advisories/mfsa2026-04/
- https://www.mozilla.org/security/advisories/mfsa2026-05/
- https://access.redhat.com/errata/RHSA-2026:0667
- https://access.redhat.com/errata/RHSA-2026:0694
- https://access.redhat.com/errata/RHSA-2026:0924
- https://access.redhat.com/errata/RHSA-2026:1320
- https://access.redhat.com/errata/RHSA-2026:1413
- https://access.redhat.com/errata/RHSA-2026:1414
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z