Description Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Exploitability: 3.9 | Impact: 5.9 Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages3 packages
🔴 Vulnerability Details3 OSV CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the Graphics component ↗ 2026-01-13 ▶ GHSA GHSA-r38v-527h-36cj: Sandbox escape due to incorrect boundary conditions in the Graphics component ↗ 2026-01-13 ▶ CVEList Sandbox escape due to incorrect boundary conditions in the Graphics component ↗ 2026-01-13 ▶
📋 Vendor Advisories8 Ubuntu Thunderbird vulnerabilities ↗ 2026-02-02 ▶ Red Hat firefox: thunderbird: Sandbox escape due to incorrect boundary conditions in the Graphics component ↗ 2026-01-13 ▶ Debian CVE-2026-0879: firefox - Sandbox escape due to incorrect boundary conditions in the Graphics component. T... ↗ 2026 ▶ Mozilla Mozilla Foundation Security Advisory 2026-01: CVE-2026-0879 ↗ ▶ Mozilla Mozilla Foundation Security Advisory 2026-02: CVE-2026-0879 ↗ ▶ Show 3 more
🕵️ Threat Intelligence1 Wiz CVE-2026-0879 Impact, Exploitability, and Mitigation Steps | Wiz ↗ ▶