Executive brief
Firefox and Thunderbird contain incorrect boundary condition checks in their process sandboxing security component, which isolates browser processes to limit the impact of exploits. An attacker could potentially bypass these sandbox restrictions to access system resources or escalate privileges on an affected user's computer, undermining the browser's core security isolation mechanism.
Technical details
An incorrect boundary condition vulnerability in the Security: Process Sandboxing component allows attackers to bypass sandbox restrictions through flawed memory access boundary checks. The vulnerability is reachable over the network without requiring user interaction or prior authentication. Successful exploitation could allow an attacker to escape the sandbox environment and gain unauthorized access to protected system resources or escalate privileges. The vulnerability has been patched in Firefox 156 and Thunderbird 156.
Affected products
- Mozilla Firefox before 156
- Mozilla Thunderbird before 156
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156