Junglewise Threat Intelligence

CVE-2026-0881: Mozilla Firefox and Thunderbird sandbox escape in Messaging System

CVE-2026-0881 · Severity: critical · CVSS 10 · Published 2026-01-13

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability has been identified in the Mozilla Firefox web browser and Thunderbird email client. The flaw exists in the messaging system component, which handles internal notifications and user interface messages. If exploited, this could allow a malicious website to bypass security 'sandbox' protections, potentially gaining unauthorized access to the underlying operating system or sensitive user data.

Technical details

A sandbox escape vulnerability exists in the Messaging System component of Firefox and Thunderbird. The root cause is that the BackupUI actor fails to verify if incoming messages originate from a privileged process. An attacker who has already compromised a content process could load a specific internal document (spotlight.html) to trigger the BackupUI actor and send unauthorized messages. This could allow the attacker to bypass sandbox restrictions and perform privileged actions, such as modifying backup passwords or disabling security features. The fix, introduced in version 147, implements a check to ensure the actor only processes messages from privileged 'about:' contexts.

Affected products

  • Mozilla Firefox < 147
  • Mozilla Thunderbird < 147

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory
  • 2026-01-13: patched

References

Related threats