CVE-2026-0880
8.8Mozilla · Firefox, Thunderbird
A sandbox escape vulnerability exists in the Graphics component due to an integer overflow, potentially allowing an attacker to bypass security restrictions.
Executive summary
An integer overflow vulnerability in the Mozilla Graphics component allows for sandbox escapes, posing a high risk of complete system compromise.
Vulnerability
The vulnerability involves an integer overflow within the Graphics component. Per the CVSS vector, this is an unauthenticated, network-accessible flaw that requires user interaction to trigger, yet results in total confidentiality, integrity, and availability impact.
Business impact
Successful exploitation of this flaw allows an attacker to escape the browser sandbox, potentially leading to arbitrary code execution on the underlying host system. Given the CVSS score of 8.8, this vulnerability represents a significant threat to organizational security, as it could facilitate unauthorized data access or the installation of persistent malware within the user environment.
Remediation
Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to the identified fixed versions: 147 for standard editions or the specified ESR releases.
Proactive Monitoring: Monitor endpoint logs for unusual child process creation or unexpected system calls originating from browser-related processes.
Compensating Controls: While no direct virtual patch exists, maintain robust endpoint detection and response (EDR) solutions to identify and block suspicious process execution resulting from browser exploitation.
Exploitation status
Public Exploit Available: No — exploit_available (unknown).
Analyst recommendation
This vulnerability carries a high severity rating and requires immediate attention to prevent potential system compromise. Administrators should prioritize the deployment of the Mozilla security updates across all workstations and servers to ensure users are protected against this sandbox escape vector.
More Mozilla CVEs
Sources
Originally found and disclosed by Oskar L, per the CVE Program record.