CVE-2026-4689
Critical · CVSS 10.0Firefox / Thunderbird (XPCOM) — Sandbox escape via integer overflow and incorrect boundary conditions in XPCOM (CWE-190, CWE-754, CWE-120)
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-190, CWE-754, CWE-120, CWE-190, CWE-190
Description
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Search profile — drives PoC discovery
Symbols XPCOMsandbox escapeinteger overflowboundary conditionsmfsa2026-20mfsa2026-21mfsa2026-22mfsa2026-23bug 2016374
Keywords CVE-2026-4689Firefox sandbox escapeXPCOM integer overflowFirefox 149 vulnerabilityFirefox ESR 115.34Firefox ESR 140.9Thunderbird 149Thunderbird 140.9mfsa2026-20bugzilla 2016374CWE-190 FirefoxXPCOM boundary conditions overflow
Versions: Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, Thunderbird < 140.9
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2016374
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-21/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930
- https://access.redhat.com/errata/RHSA-2026:5931
- https://access.redhat.com/errata/RHSA-2026:5932
- https://access.redhat.com/errata/RHSA-2026:6188
- https://access.redhat.com/errata/RHSA-2026:6342
- https://access.redhat.com/errata/RHSA-2026:6917
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z