CVE-2026-0878
8.0Mozilla · Firefox, Thunderbird
A sandbox escape vulnerability exists in the Graphics: CanvasWebGL component of Mozilla Firefox and Thunderbird due to incorrect boundary conditions.
Executive summary
A critical sandbox escape vulnerability in Mozilla Firefox and Thunderbird allows an attacker to bypass security boundaries, potentially leading to unauthorized system access.
Vulnerability
The flaw resides in the Graphics: CanvasWebGL component, where incorrect boundary conditions permit a sandbox escape. This vulnerability requires a user to interact with malicious content, as it is triggered via network interaction with user involvement.
Business impact
A successful exploit allows an attacker to break out of the application sandbox, which may lead to full compromise of the user workstation or the execution of arbitrary code within the host operating system. Given the CVSS score of 8.0, this represents a high-severity risk that could result in significant data theft, unauthorized system control, or lateral movement within the corporate network.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 147 or the ESR version 140.7 immediately to incorporate the necessary security patches.
Proactive Monitoring: Review endpoint security logs for unusual process execution patterns or abnormal memory activity originating from web browser processes.
Compensating Controls: Ensure that endpoint protection software is active and configured to block suspicious child processes spawned by browser-related applications.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a significant risk to organizational endpoints by undermining the primary security isolation mechanism of the browser. IT administrators should prioritize the deployment of the Mozilla security updates to all managed workstations to eliminate this path for potential system-level compromise.
More Mozilla CVEs
Sources
Originally found and disclosed by Oskar L, per the CVE Program record.