Junglewise Threat Intelligence

CVE-2026-4689: Mozilla Firefox and Thunderbird sandbox escape in XPCOM

CVE-2026-4689 · Severity: critical · CVSS 10 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular web browsers and email clients used for accessing the internet and managing communications. A critical vulnerability in these applications could allow an attacker to bypass security 'sandbox' protections that normally isolate the browser from the rest of the computer. If exploited, this could lead to unauthorized access to sensitive user data or the ability to run malicious software on the victim's system.

Technical details

A critical vulnerability exists in the XPCOM component of Mozilla Firefox and Thunderbird due to an integer overflow and incorrect boundary conditions. This flaw allows for a sandbox escape, potentially enabling an attacker to execute code outside of the restricted browser environment. The vulnerability can be triggered remotely, and according to some CVSS assessments, may not require user interaction. Patches are available in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and Thunderbird versions 149 and 140.9.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 115.34, < 140.9
  • Mozilla Thunderbird < 149, < 140.9

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: patched

References

Related threats