CVSS 10.0CVSS 10.0 · CRITICAL
CVE-2026-75874Escape de sandbox en Firefox y Thunderbird
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Ver en NVDAnálisis
Esta vulnerabilidad permite un escape de sandbox en el componente Remote Settings Client de Firefox y Thunderbird. Un atacante podría ejecutar código malicioso fuera de las restricciones de seguridad del navegador para comprometer el sistema operativo del usuario. Se recomienda actualizar inmediatamente a la versión 154 o superior.
Roles relevantes
FrontendJavascriptCyberSecurityLinuxWindowsMacos
Severidad
Puntaje: 10.0(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE):
CWE-693EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Publicada: 18/8/2026, 13:17:43
Última modificación: 18/8/2026, 20:17:32