VDB

GHSA-j5qx-hh9g-j6wj

GHSA-j5qx-hh9g-j6wj PUBLISHED CVSS 10 CRITICAL

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.

Risk Scores

CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Timeline

  • Mar 24, 2026 CVE Published
  • Apr 10, 2026 Security Advisory
  • Jun 30, 2026 CVE Updated
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›