CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-4692

Critical · CVSS 10.0

Mozilla Firefox / Thunderbird — Sandbox escape

CVSS
10.0
nvd
EPSS
KEV
No
Class
other
NVD-CWE-noinfo, CWE-653

Description

Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Search profile — drives PoC discovery

Symbols Responsive Design ModeRDMmfsa2026-20mfsa2026-21mfsa2026-22mfsa2026-23bug 2017643
Keywords CVE-2026-4692Firefox sandbox escapeResponsive Design Mode sandboxFirefox RDM exploitFirefox 149 sandbox bypassThunderbird 140.9 sandbox escapemfsa2026-20 PoCCWE-653 sandbox escape Firefox
Versions: Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, Thunderbird < 140.9

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z