Mozilla Firefox and Thunderbird WebRender Component Sandbox Escape Vulnerability

Vulnerability

A sandbox escape vulnerability has been identified in the WebRender component of Mozilla Firefox and Thunderbird. This issue arises from incorrect boundary conditions, allowing for potential unauthorized access or actions within the application sandbox. The vulnerability affects multiple versions of Firefox and Thunderbird, including Firefox versions prior to 148, Firefox ESR versions prior to 115.33 and 140.8, as well as Thunderbird versions prior to 148 and 140.8.

Impact

Exploitation of this vulnerability leads to a sandbox escape, allowing potentially malicious actions or access to resources that are normally restricted within the application sandbox.

Remediation

Users can upgrade to Firefox 148 or Thunderbird 148. For Firefox ESR users, version 140.8 is available. Instructions for updating can be found in the Firefox Release Notes and the Thunderbird Release Notes.

Added: Feb 24, 2026, 2:57 PM
Updated: Feb 24, 2026, 11:00 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.