Executive brief
A security vulnerability exists in Mozilla Firefox and Thunderbird that could allow an attacker to bypass the browser's security sandbox. This sandbox is a critical layer of defense designed to prevent malicious websites from accessing the rest of your computer. If exploited, an attacker could potentially gain unauthorized access to your system or data after a user visits a specially crafted website.
Technical details
An out-of-bounds read vulnerability exists in the Graphics: CanvasWebGL component of Mozilla browsers due to incorrect boundary conditions when handling shared memory. Specifically, the 'SourceSurfaceSharedDataWrapper::Init' function fails to properly validate the length of shared memory handles against the requested surface size, leading to an out-of-bounds read during texture uploads in 'ConvertImage'. An attacker can exploit this by providing a malicious texture via shared memory, potentially achieving a sandbox escape. The attack requires network reachability and user interaction (visiting a malicious site) and is mitigated by the high complexity of the shared memory manipulation required. Patches are available in Firefox 147, Firefox ESR 140.7, and corresponding Thunderbird versions.
Affected products
- Mozilla Firefox < 147
- Mozilla Firefox ESR < 140.7
- Mozilla Thunderbird < 147
- Mozilla Thunderbird ESR < 140.7
- Red Hat Enterprise Linux Server (v. 7 ELS) affected
- Red Hat Enterprise Linux AppStream (v. 10) affected
Timeline
- 2026-01-13: advisory: Mozilla Foundation Security Advisory published
- 2026-01-13: patched: Fixed in Firefox 147 and Thunderbird 147
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2003989
- https://www.mozilla.org/security/advisories/mfsa2026-01/
- https://www.mozilla.org/security/advisories/mfsa2026-03/
- https://www.mozilla.org/security/advisories/mfsa2026-04/
- https://www.mozilla.org/security/advisories/mfsa2026-05/
- https://access.redhat.com/errata/RHSA-2026:0667
- https://access.redhat.com/errata/RHSA-2026:0694