CVE-2026-2760

Critical
|10.0
Exploit Available

Plain English Summary

AI-powered analysis for quick understanding

This critical vulnerability allows an attacker to break out of a secure area in Firefox and Thunderbird, potentially gaining access to sensitive system resources. It affects versions prior to 148 for Firefox and 148 for Thunderbird, meaning users need to update their software to stay protected.

Technical Description

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$15,000($5K-$15K)
Vendor Response
Grade APatched in 2 days

Quick Information

Published

Feb 24, 2026

about 1 month ago

Last Modified

Feb 26, 2026

about 1 month ago

Vendor

mozilla

Product

firefox

Related Vulnerabilities

CVE-2026-2785Critical

This vulnerability allows an attacker to potentially execute malicious code on a user's system through Firefox or Thunderbird, which could lead to full control over the affected device. It specifically affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.

CVE-2026-2784Critical

This critical vulnerability allows an attacker to bypass security measures in Firefox and Thunderbird, potentially leading to unauthorized access or manipulation of sensitive information. It affects users running versions earlier than 148 for Firefox and 148 for Thunderbird, meaning those who haven't updated their software are at risk.

CVE-2026-2783High

This vulnerability allows an attacker to access sensitive information from a user's system through a flaw in Firefox's JavaScript engine. It affects versions of Firefox and Thunderbird before 148 and 140.8, meaning users need to update their software to protect against potential data leaks.

CVE-2026-2782Critical

This critical vulnerability allows an attacker to gain higher access privileges within Firefox and Thunderbird, potentially letting them execute harmful actions on a user's system. It affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.

CVE-2026-2781Critical

This critical vulnerability allows an attacker to potentially execute malicious code on a user's system through affected versions of Firefox and Thunderbird. It requires the user to visit a specially crafted website or open a malicious email, making it essential for users to update their software to the latest versions to stay protected.