Junglewise Threat Intelligence

CVE-2026-4690: Mozilla Firefox and Thunderbird sandbox escape in XPCOM

CVE-2026-4690 · Severity: high · CVSS 8.6 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular web browsing and email applications. A security vulnerability has been identified that could allow an attacker to bypass the software's built-in security sandbox. If exploited, this could lead to unauthorized access to the underlying operating system, potentially compromising user data or system stability.

Technical details

An integer overflow and incorrect boundary condition vulnerability exists within the Cross Platform Object Model (XPCOM) component of Mozilla products. The flaw allows for a sandbox escape, enabling an attacker to break out of the restricted browser environment. The vulnerability is reachable via network-based vectors and does not require prior authentication. Mozilla has addressed this issue in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and Thunderbird versions 149 and 140.9.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 115.34, < 140.9
  • Mozilla Thunderbird < 149, < 140.9

Timeline

  • 2026-03-24: advisory: Mozilla published security advisories MFSA2026-20, MFSA2026-21, and MFSA2026-22.
  • 2026-03-24: patched: Fixes released in Firefox 149 and related ESR/Thunderbird versions.

References

Related threats