Executive brief
Firefox and Thunderbird are web browsers and email clients used by millions of users for browsing the internet and managing email. A vulnerability in the Widget: Win32 component allows an attacker to escape the browser's security sandbox, potentially enabling them to gain unauthorized access to the user's system, steal sensitive data, or execute malicious code with elevated privileges.
Technical details
This is a sandbox escape vulnerability in the Widget: Win32 component caused by incorrect boundary conditions. The vulnerability allows an attacker to break out of the browser's security sandbox through improper memory access validation in the Win32 widget layer. The attack is network-accessible and does not require authentication or user interaction beyond normal browsing. A successful exploit enables arbitrary code execution at the privilege level of the affected process, potentially compromising the entire system. Mozilla has patched this vulnerability in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird ESR before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3