Executive brief
A security vulnerability has been identified in the Telemetry component of Mozilla Firefox and Thunderbird. This flaw could allow a malicious website or email to bypass the browser's security sandbox, which is designed to isolate the application from the rest of the computer. If exploited, an attacker could potentially gain unauthorized access to the underlying operating system, compromising the security and integrity of the user's device.
Technical details
A sandbox escape vulnerability exists in the Telemetry component of Mozilla Firefox and Thunderbird due to improper check for unusual or exceptional conditions (CWE-754) and incorrect boundary conditions. The vulnerability allows a process within the restricted sandbox environment to break out and interact with the host operating system. While the NVD CVSS vector suggests a primary impact on availability, the nature of a sandbox escape typically facilitates unauthorized access or code execution on the host. The issue is triggered by processing malicious content that exploits these boundary condition errors. Patches are available in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and Thunderbird 149/140.9.
Affected products
- Mozilla Firefox < 149
- Mozilla Firefox ESR < 115.34, < 140.9
- Mozilla Thunderbird < 149, < 140.9
Timeline
- 2026-03-24: disclosed
- 2026-03-24: advisory
- 2026-03-24: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2016368
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-21/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930