Executive brief
Firefox web browser contains a sandbox escape vulnerability in its Graphics component caused by an invalid pointer. This flaw allows an attacker to break out of the browser's security sandbox and gain elevated privileges, potentially leading to unauthorized access to system resources and data. The vulnerability affects multiple versions of Firefox, Firefox ESR, and Thunderbird email client.
Technical details
The vulnerability is a sandbox escape due to invalid pointer handling in the Graphics component. It affects Firefox versions prior to 156, Firefox ESR versions prior to 140.16 and 153.3, Thunderbird versions prior to 156, 140.16, and 153.3. The flaw is triggered through graphics rendering operations that Firefox processes during normal web browsing. An attacker can exploit this via a malicious web page or crafted content to escape the sandbox and execute arbitrary code with elevated privileges. Patches have been released in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 140.16, before 153.3
- Mozilla Thunderbird before 156, before 140.16, before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, Thunderbird 153.3