Junglewise Threat Intelligence

CVE-2026-75874: Mozilla Firefox Remote Settings Client sandbox escape

CVE-2026-75874 · Severity: critical · CVSS 10 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox, Thunderbird, and related products contain a sandbox escape vulnerability in the Remote Settings Client component, which manages automatic browser and extension configuration updates. An attacker can exploit this to break out of the sandbox and execute arbitrary code with full browser privileges, compromising user data, credentials, and system security.

Technical details

The Remote Settings Client component in Firefox and Thunderbird is vulnerable to a sandbox escape that allows attackers to bypass process isolation and gain code execution outside the sandbox. The vulnerability is in the client-side handling of remote configuration updates, likely due to improper validation or unsafe deserialization of settings fetched from Mozilla's remote configuration service. An unauthenticated network attacker can trigger the vulnerability, potentially through malicious settings delivery or by compromising the update mechanism. Exploitation enables arbitrary code execution with full browser privileges, allowing theft of credentials, cookies, and local files. Mozilla patched the vulnerability in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2, released on August 18, 2026.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR 115 before 115.40, 140 before 140.15, 153 before 153.2
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR 140 before 140.15, 153 before 153.2

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched

References

Related threats