Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
Info
Summary
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061245
- https://www.mozilla.org/security/advisories/mfsa2026-90/
- https://www.mozilla.org/security/advisories/mfsa2026-93/
- https://www.mozilla.org/security/advisories/mfsa2026-94/
Timeline
- nvd_ingest NVD