VYPR
Critical severity9.8NVD Advisory· Published Jan 13, 2026· Updated Apr 13, 2026

CVE-2026-0879

CVE-2026-0879

Description

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

Affected products

4
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*range: <147.0
    • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*range: <115.32.0
  • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*range: <147.0
    • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*range: <140.7.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.