Back

CRITICAL

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component

Published Mar 24, 2026

Description

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Mar 24, 2026
Updated Jul 15, 2026
Reserved Mar 23, 2026
CISA Vulnrichment
Updated Mar 25, 2026
NVD
Status Modified
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Mar 24, 2026