Executive brief
Firefox and Thunderbird web browsers contain a sandbox escape vulnerability in the Widget component that processes Windows graphics and UI operations. An attacker can exploit incorrect boundary condition checks to break out of the browser's security sandbox and execute arbitrary code with browser privileges, potentially leading to system compromise or unauthorized access to sensitive data.
Technical details
This vulnerability is a sandbox escape caused by incorrect boundary conditions in the Widget: Win32 component, which handles Windows-specific UI rendering and input processing. The flaw allows an attacker to bypass security boundaries that normally restrict browser code execution to a sandboxed environment. The attack requires network access to deliver malicious content to the browser, typically via a compromised or attacker-controlled website. Successful exploitation results in code execution with the privileges of the Firefox or Thunderbird process, potentially enabling unauthorized system access or data exfiltration. The vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed: Vulnerability announced by Mozilla
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3