Executive brief
Firefox's sandboxing mechanism, which isolates untrusted web content to prevent attackers from accessing the wider system, contains a flaw in the Windows widget handling code. An attacker could escape the sandbox and gain the same privileges as the Firefox browser process, potentially leading to system compromise or theft of user data. This vulnerability affects Firefox on Windows systems.
Technical details
The vulnerability is a sandbox escape caused by incorrect boundary conditions in the Widget: Win32 component. The flaw allows an attacker to break out of the sandboxed renderer process and gain the privileges of the Firefox parent process. Attack prerequisites are minimal—a user simply needs to visit a malicious website or open malicious content in Firefox. The vulnerability has been patched in Firefox 156 and Firefox ESR 153.3. No public exploit code is currently known to be in active use.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed: Published in Mozilla Security Advisory MFSA2026-90
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3