Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-75874Sandbox escape in Firefox and Thunderbird

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

View on NVD

Analysis

Esta vulnerabilidad permite un escape de sandbox en el componente Remote Settings Client de Firefox y Thunderbird. Un atacante podría ejecutar código malicioso fuera de las restricciones de seguridad del navegador para comprometer el sistema operativo del usuario. Se recomienda actualizar inmediatamente a la versión 154 o superior.

Relevant roles

FrontendJavascriptCyberSecurityLinuxWindowsMacos

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-693

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

Published: 8/18/2026, 1:17:43 PM
Last modified: 8/18/2026, 8:17:32 PM

References

HomeEventsBlogResourcesCoursesTeam