Junglewise Threat Intelligence

CVE-2026-0880: Mozilla Firefox and Thunderbird sandbox escape in Graphics component

CVE-2026-0880 · Severity: high · CVSS 8.8 · Published 2026-01-13

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability in Mozilla Firefox and Thunderbird could allow an attacker to bypass the browser's security sandbox. This sandbox is a critical layer of defense designed to prevent malicious websites from accessing the rest of your computer. If exploited, typically by a user visiting a specially crafted website, an attacker could potentially gain unauthorized access to the underlying operating system or sensitive user data.

Technical details

An integer overflow vulnerability exists in the 'CopyToImageSurface' function within the Graphics component of Mozilla Gecko-based applications. The flaw occurs when calculating memory offsets using 32-bit integers (y * surfStride), which can result in a signed integer overflow and subsequent sign extension. This leads to an out-of-bounds write (OOBW) or read (OOBR) when 'memcpy' is called, as the destination pointer can be incorrectly calculated to point before the allocated buffer. An attacker can leverage this memory corruption to achieve a sandbox escape. The vulnerability is reachable via web content and requires user interaction (e.g., visiting a malicious page). Patches are available in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, and corresponding Thunderbird versions.

Affected products

  • Mozilla Firefox < 147
  • Mozilla Firefox ESR < 115.32, < 140.7
  • Mozilla Thunderbird < 147, < 140.7

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: patched: Fixed in Firefox 147 and ESR releases

References

Related threats