Executive brief
Firefox is a widely-used web browser that processes web content and executes web applications. This vulnerability allows an attacker to escape the browser sandbox and gain elevated privileges on the user's system by exploiting incorrect boundary condition checks in the Graphics rendering component. A successful exploit could allow attackers to steal sensitive data, install malware, or take full control of the affected computer.
Technical details
The vulnerability is a privilege escalation bug caused by incorrect boundary condition handling in Mozilla Firefox's Graphics component. The flaw allows an attacker to bypass sandbox restrictions and execute code with elevated privileges. The attack requires local network access or user interaction to trigger, and does not require authentication. An attacker who successfully exploits this vulnerability can break out of the browser's security sandbox and gain system-level access. Mozilla has released patches in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.
Affected products
- Mozilla Firefox ESR below 115.41 and below 140.16
- Mozilla Thunderbird below 140.16
Timeline
- 2026-09-15: disclosed