Junglewise Threat Intelligence

CVE-2026-2768: Mozilla Firefox and Thunderbird sandbox escape in IndexedDB

CVE-2026-2768 · Severity: critical · CVSS 10 · Published 2026-02-24

Technologies: Red Hat Enterprise Linux AppStream, Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Red Hat, Mozilla.

Executive brief

A critical security vulnerability has been identified in Mozilla Firefox and Thunderbird's IndexedDB component, which is used by websites to store data locally in the browser. This flaw allows a malicious website or a compromised browser process to bypass security 'sandboxing' protections that normally keep web content isolated from the rest of the computer. If exploited, an attacker could gain full control over the user's system, potentially leading to the theft of sensitive data, installation of malware, or complete service disruption.

Technical details

A heap out-of-bounds (OOB) write vulnerability exists in the 'Storage: IndexedDB' component of Mozilla browsers. The root cause is a failure to validate 'mAutoIncrementKeyOffsets' during IPC deserialization in 'dom/indexedDB/SerializationHelpers.h'. A compromised content process can forge an 'ObjectStoreAddParams' IPC message with arbitrary offset values. When the parent process processes this message via 'MaybeUpdateAutoIncrementKey', it performs an 8-byte write at an attacker-controlled offset relative to the 'mBuffer' data pointer. This allows for an arbitrary relative heap write in the parent process, facilitating a full sandbox escape. The vulnerability is fixed in Firefox 148, Firefox ESR 140.8, and Thunderbird 148/140.8.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Firefox ESR < 140.8
  • Mozilla Thunderbird < 148
  • Mozilla Thunderbird ESR < 140.8
  • Red Hat Red Hat Enterprise Linux Server 7 ELS affected
  • Red Hat Red Hat Enterprise Linux AppStream EUS 10.0 affected

Timeline

  • 2026-02-24: advisory: Mozilla Foundation Security Advisory 2026-13 published.
  • 2026-02-24: patched: Fixed in Firefox 148 and related versions.

References

Related threats