Executive brief
A critical security vulnerability has been identified in Mozilla Firefox and Thunderbird that could allow an attacker to escape the browser's security sandbox. This flaw occurs when the software incorrectly handles specific data structures used for web content, potentially allowing a malicious website to execute code outside of the restricted browser environment. If exploited, this could lead to full system compromise, unauthorized data access, or the installation of malware on a user's computer.
Technical details
A heap-based out-of-bounds (OOB) read vulnerability exists in the 'DOM: Core & HTML' component of Mozilla products. The flaw is located in 'StructuredCloneBlob::Holder::ReadStructuredCloneInternal' within 'StructuredCloneBlob.cpp', where 'blobOffset' and 'blobCount' are read from an attacker-controlled buffer without sufficient source bounds checking. When 'AppendElements' is called, it performs an uninitialized copy of elements based on these controlled values. An attacker can provide a crafted 'blobCount' to trigger an OOB read on the heap; because the copied elements are treated as 'RefPtr<BlobImpl>', the subsequent 'AddRef()' call on garbage memory can lead to a sandbox escape and arbitrary code execution. The vulnerability is reachable via Inter-Process Communication (IPC) from a compromised content process to the parent process.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 115.33, < 140.8
- Mozilla Thunderbird < 148, < 140.8
- Red Hat Red Hat Enterprise Linux Server 7 ELS
Timeline
- 2026-02-24: advisory: Mozilla Foundation Security Advisory published
- 2026-02-24: patched: Fixed in Firefox 148 and ESR releases
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2016358
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338