Executive brief
A critical security vulnerability has been identified in Mozilla Firefox and Thunderbird's graphics processing component. This flaw could allow a malicious website or email to bypass the browser's security sandbox, which is designed to isolate web content from the rest of the computer. If exploited, an attacker could potentially gain unauthorized access to the user's system, leading to data theft or the installation of malicious software.
Technical details
A memory safety vulnerability exists in the Graphics component of Mozilla browsers, specifically within the 'CopyToImageSurface' function used during Cairo rendering. The flaw is caused by incorrect boundary conditions when handling incompatible surface format conversions (e.g., converting HSV to ARGB32). When a surface requires a new allocation due to an invalid stride, the 'GfxFormatToCairoFormat' function may default to a 4-byte-per-pixel format while the source data uses a larger byte-per-pixel value. This discrepancy leads to an out-of-bounds write (OOBW) during the 'memcpy' operation, which can be leveraged to achieve a sandbox escape. The vulnerability is reachable via the 'PRemotePrintJob' actor during drawing operations. Fixes are available in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, and Thunderbird 147/140.7.
Affected products
- Mozilla Firefox ESR < 115.32, < 140.7
- Mozilla Firefox < 147
- Mozilla Thunderbird < 147, < 140.7
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched
- 2026-01-13: advisory
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2004602
- https://www.mozilla.org/security/advisories/mfsa2026-01/
- https://www.mozilla.org/security/advisories/mfsa2026-02/
- https://www.mozilla.org/security/advisories/mfsa2026-03/
- https://www.mozilla.org/security/advisories/mfsa2026-04/
- https://www.mozilla.org/security/advisories/mfsa2026-05/
- https://access.redhat.com/errata/RHSA-2026:0667