Executive brief
Firefox's WebRTC component contains a flaw that allows attackers to escape the browser's security sandbox through incorrect boundary checking. This could allow malicious web content to break out of the browser's isolation layer and access protected system resources or sensitive user data.
Technical details
A boundary condition vulnerability exists in Firefox's WebRTC component that permits sandbox escape. The vulnerability stems from incorrect validation of memory or data boundaries in the WebRTC implementation, allowing an attacker to bypass the sandbox through memory corruption or out-of-bounds access. The attack requires network access (visiting a malicious website); no user interaction beyond visiting the site is needed. A successful exploit grants an attacker escape from the browser sandbox, potentially enabling arbitrary code execution outside browser restrictions. Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3 contain the fix.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3