Firefox <149 XPCOM Sandbox Escape (CVE-2026-4690)
CVE-2026-4690 Published on March 24, 2026

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

NVD


Products Associated with CVE-2026-4690

Want to know whenever a new CVE is published for Mozilla products? stack.watch will email you.

 
 
 

Affected Versions

Mozilla Firefox: Mozilla Firefox ESR: Mozilla Firefox ESR: Mozilla Thunderbird: Mozilla Thunderbird: