CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-2776

Critical · CVSS 10.0

Mozilla Firefox / Thunderbird — Sandbox escape via incorrect boundary conditions (buffer overflow/memory safety) in Telemetry component

CVSS
10.0
nvd
EPSS
KEV
No
Class
oss containerizable
NVD-CWE-noinfo, CWE-119

Description

Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

Search profile — drives PoC discovery

Symbols Telemetrysandbox escapeboundary conditionsCWE-119mfsa2026-13mfsa2026-14mfsa2026-15mfsa2026-16bugzilla 2015266
Keywords CVE-2026-2776Firefox sandbox escapeThunderbird sandbox escapeTelemetry boundary conditionFirefox 148 vulnerabilityFirefox ESR 115.33Firefox ESR 140.8Thunderbird 148Thunderbird 140.8mfsa2026-13mfsa2026 TelemetryMozilla sandbox bypass TelemetryCWE-119 Firefox Telemetry
Versions: Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, Thunderbird < 140.8

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T00:30:14.000Z