CVE-2026-2776
Critical · CVSS 10.0Mozilla Firefox / Thunderbird — Sandbox escape via incorrect boundary conditions (buffer overflow/memory safety) in Telemetry component
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- NVD-CWE-noinfo, CWE-119
Description
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
Search profile — drives PoC discovery
Symbols Telemetrysandbox escapeboundary conditionsCWE-119mfsa2026-13mfsa2026-14mfsa2026-15mfsa2026-16bugzilla 2015266
Keywords CVE-2026-2776Firefox sandbox escapeThunderbird sandbox escapeTelemetry boundary conditionFirefox 148 vulnerabilityFirefox ESR 115.33Firefox ESR 140.8Thunderbird 148Thunderbird 140.8mfsa2026-13mfsa2026 TelemetryMozilla sandbox bypass TelemetryCWE-119 Firefox Telemetry
Versions: Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, Thunderbird < 140.8
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2015266
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338
- https://access.redhat.com/errata/RHSA-2026:3339
- https://access.redhat.com/errata/RHSA-2026:3361
- https://access.redhat.com/errata/RHSA-2026:3491
- https://access.redhat.com/errata/RHSA-2026:3492
- https://access.redhat.com/errata/RHSA-2026:3493
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z