Executive brief
A security vulnerability has been identified in the Mozilla Firefox web browser and Thunderbird email client. The flaw exists in the messaging system component, which handles internal notifications and user interface messages. If exploited, this could allow a malicious website to bypass security 'sandbox' protections, potentially gaining unauthorized access to the underlying operating system or sensitive user data.
Technical details
A sandbox escape vulnerability exists in the Messaging System component of Firefox and Thunderbird. The root cause is that the BackupUI actor fails to verify if incoming messages originate from a privileged process. An attacker who has already compromised a content process could load a specific internal document (spotlight.html) to trigger the BackupUI actor and send unauthorized messages. This could allow the attacker to bypass sandbox restrictions and perform privileged actions, such as modifying backup passwords or disabling security features. The fix, introduced in version 147, implements a check to ensure the actor only processes messages from privileged 'about:' contexts.
Affected products
- Mozilla Firefox < 147
- Mozilla Thunderbird < 147
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory
- 2026-01-13: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2005845
- https://www.mozilla.org/security/advisories/mfsa2026-01/
- https://www.mozilla.org/security/advisories/mfsa2026-04/
- https://access.redhat.com/security/cve/CVE-2026-0881
- https://bugzilla.redhat.com/show_bug.cgi?id=2428970
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0881.json