Executive brief
A critical security vulnerability has been identified in Mozilla Firefox and Thunderbird's Responsive Design Mode, a tool used by developers to test how websites look on different screen sizes. This flaw allows a malicious website to break out of the browser's security sandbox, which is designed to keep web content isolated from the rest of your computer. If exploited, an attacker could potentially gain unauthorized access to your local files, sensitive data, or take control of the underlying operating system.
Technical details
A sandbox escape vulnerability exists in the Responsive Design Mode (RDM) component of Mozilla browsers and mail clients. The flaw is categorized under CWE-653 (Improper Isolation or Compartmentalization) and allows web content to bypass the security boundaries intended to restrict it to the browser process. While specific root cause details are restricted in the associated Bugzilla report (Bug 2017643), the vulnerability is reachable via network vectors and carries a CVSS 3.1 score of 10.0 due to the potential for full system compromise (Scope Change). Patches are available in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and corresponding Thunderbird releases.
Affected products
- Mozilla Firefox < 149
- Mozilla Firefox ESR < 115.34, < 140.9
- Mozilla Thunderbird < 149, < 140.9
- Red Hat Enterprise Linux Server (v. 7 ELS) affected
Timeline
- 2026-03-24: advisory: Mozilla Foundation Security Advisories MFSA2026-20 through MFSA2026-24 published.
- 2026-03-24: patched: Fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2017643
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-21/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930