CVE-2025-14322
8.0Mozilla · Firefox, Thunderbird
A sandbox escape vulnerability exists in the Graphics: CanvasWebGL component of Mozilla Firefox and Thunderbird, potentially allowing attackers to bypass security restrictions.
Executive summary
A critical sandbox escape vulnerability in Mozilla Firefox and Thunderbird allows remote attackers to bypass security boundaries, creating a significant risk of system compromise.
Vulnerability
The flaw is an incorrect boundary condition in the Graphics: CanvasWebGL component. This vulnerability is remotely exploitable and does not require authentication, though it does require user interaction to trigger.
Business impact
Successful exploitation of this sandbox escape allows an attacker to break out of the browser security sandbox, potentially leading to unauthorized execution of code on the underlying host operating system. Given the CVSS score of 8.0, this represents a high-severity risk that could lead to full system compromise, data exfiltration, or the installation of persistent malicious software.
Remediation
Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to the versions specified in the vendor security advisories (MFSA 2025-92 through 2025-96) to apply the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected child processes originating from the browser or email client.
Compensating Controls: Ensure that systems are running with the principle of least privilege, as this limits the potential impact of a successful sandbox escape if the user account does not have administrative rights.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
The severity of this flaw necessitates immediate attention. IT administrators should prioritize the deployment of the latest updates for Firefox and Thunderbird across all managed workstations to eliminate the sandbox escape vector. Failure to update leaves the host environment vulnerable to potential remote code execution attacks initiated through web or email content.
More Mozilla CVEs
Sources
Originally found and disclosed by Oskar L, per the CVE Program record.