Executive brief
Firefox and Thunderbird's Safe Browsing component, which helps protect users from malicious websites and downloads, contains an incorrect boundary conditions vulnerability. An attacker could exploit this flaw to bypass security checks, potentially allowing malicious content to reach end users despite the protection system being in place.
Technical details
The vulnerability is an incorrect boundary conditions flaw in the Safe Browsing component that protects users from phishing and malware. The exact attack vector and specific preconditions are not detailed in available sources, but the high CVSS score of 8.0 suggests potential for privilege escalation or security bypass. The issue was patched in Firefox 156, Firefox ESR 153.3, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 153.3