← Back to CVE List
CVE-2026-100781NVD
Vulnerability Summary
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
CVSS v3.1 Base Metrics — Score 9.6 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Mozilla Firefox < 157.0.0
- Mozilla Firefox >= 115.1.0 and < 115.42.0
- Mozilla Firefox >= 140.0 and < 140.17.0
- Mozilla Firefox >= 153.0 and < 153.4.0
- Mozilla Thunderbird < 157.0
- Mozilla Thunderbird >= 140.0 and < 140.17.0
- Mozilla Thunderbird >= 153.0 and < 153.4.0
- Mozilla Firefox 157.0.0
- Mozilla Firefox 115.42.0
- Mozilla Firefox 140.17.0
- Mozilla Firefox 153.4.0
- Mozilla Thunderbird 157.0
- Mozilla Thunderbird 140.17.0
- Mozilla Thunderbird 153.4.0
External References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068434
- https://www.mozilla.org/security/advisories/mfsa2026-100/
- https://www.mozilla.org/security/advisories/mfsa2026-101/
- https://www.mozilla.org/security/advisories/mfsa2026-102/
- https://www.mozilla.org/security/advisories/mfsa2026-103/
- https://www.mozilla.org/security/advisories/mfsa2026-97/
- https://www.mozilla.org/security/advisories/mfsa2026-98/
- https://www.mozilla.org/security/advisories/mfsa2026-99/