CVE-2026-0881Improper Access Control in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
0.0%
top 91.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages2 packages

NVDmozilla/firefox< 147.0
NVDmozilla/thunderbird< 147.0

🔴Vulnerability Details

3
OSV
CVE-2026-0881: Sandbox escape in the Messaging System component2026-01-13
GHSA
GHSA-cw2j-6pvw-7g9v: Sandbox escape in the Messaging System component2026-01-13
CVEList
Sandbox escape in the Messaging System component2026-01-13

📋Vendor Advisories

4
Red Hat
firefox: Sandbox escape in the Messaging System component2026-01-13
Debian
CVE-2026-0881: firefox - Sandbox escape in the Messaging System component. This vulnerability affects Fir...2026
Mozilla
Mozilla Foundation Security Advisory 2026-01: CVE-2026-0881
Mozilla
Mozilla Foundation Security Advisory 2026-04: CVE-2026-0881

🕵️Threat Intelligence

1
Wiz
CVE-2026-0881 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0881 — Improper Access Control in Mozilla | cvebase