CVSS 10.0CVSS 10.0 · CRITICAL
CVE-2026-75874Sandbox escape in Firefox and Thunderbird
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
View on NVDAnalysis
Esta vulnerabilidad permite un escape de sandbox en el componente Remote Settings Client de Firefox y Thunderbird. Un atacante podría ejecutar código malicioso fuera de las restricciones de seguridad del navegador para comprometer el sistema operativo del usuario. Se recomienda actualizar inmediatamente a la versión 154 o superior.
Relevant roles
FrontendJavascriptCyberSecurityLinuxWindowsMacos
Severity
Score: 10.0(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-693EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Published: 8/18/2026, 1:17:43 PM
Last modified: 8/18/2026, 8:17:32 PM