Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, and Firefox ESR 140.10.1.
CVSS Details
- CVSS 3.1 Base Score: 9.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-x11 | May 24, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade firefox | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | May 3, 2026 | May 3, 2026 |
| Freebsd | — | Upgrade thunderbirdUpgrade firefoxUpgrade firefox-esr | Apr 30, 2026 | Apr 29, 2026 |
| Mfsa2026 30 | — | Upgrade to Mozilla Firefox version 150.0 | Apr 29, 2026 | Apr 21, 2026 |
| Mfsa2026 36 | — | Upgrade to Mozilla Firefox ESR version 140.10.1Upgrade to the latest version of Mozilla Firefox | Apr 28, 2026 | Apr 28, 2026 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 140.10.1Upgrade to the latest version of Mozilla Thunderbird | Apr 29, 2026 | Apr 21, 2026 |
| Oracle_linux | — | Upgrade firefoxUpgrade thunderbird | May 28, 2026 | Apr 28, 2026 |
| Redhat_linux | — | Upgrade thunderbirdUpgrade thunderbird-debugsourceUpgrade firefoxUpgrade firefox-debugsourceNo solution existsUpgrade firefox-x11Upgrade firefox-debuginfoUpgrade thunderbird-debuginfo | May 20, 2026 | Apr 28, 2026 |
| Rocky_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade thunderbird-debuginfoUpgrade firefox-debuginfoUpgrade firefox-x11Upgrade thunderbird-debugsourceUpgrade firefox-debugsource | May 25, 2026 | May 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub