Junglewise Threat Intelligence

CVE-2026-2776: Mozilla Firefox and Thunderbird sandbox escape in Telemetry component

CVE-2026-2776 · Severity: critical · CVSS 10 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A critical security vulnerability has been identified in the Telemetry component of Firefox and Thunderbird on Windows systems. This flaw allows a compromised web page process to break out of its security sandbox and execute malicious code or access sensitive data in the main browser process. An exploit could lead to full system compromise, unauthorized data access, or service disruption. Users should update to the latest versions of Firefox or Thunderbird immediately to mitigate this risk.

Technical details

This vulnerability is a heap-based out-of-bounds (OOB) write and read within the Telemetry component's 'CombinedStacks' class, specifically affecting Windows installations. The root cause is a lack of cross-validation during the deserialization of IPC messages in 'ParamTraits<CombinedStacks>::Read', allowing an attacker-controlled 'mNextIndex' to be used in 'CombinedStacks::AddStacks()'. Because 'std::vector::operator[]' is used without bounds checking in release builds, a compromised content process can send a malicious 'UntrustedModulesData' response to trigger OOB memory access in the parent process. This can result in a sandbox escape, arbitrary code execution in the context of the parent process, or a denial-of-service via division-by-zero. The issue is fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, and Thunderbird 148/140.8.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Firefox ESR < 115.33, < 140.8
  • Mozilla Thunderbird < 148, < 140.8

Timeline

  • 2026-02-24: advisory: Mozilla Foundation Security Advisory 2026-13 published.
  • 2026-02-24: patched

References

Related threats