CVE-2026-4687 is a high-severity sandbox escape vulnerability (CVSS 8.6) stemming from incorrect boundary conditions in the Telemetry component of Mozilla Firefox and Thunderbird. It affects Firefox versions below 149, Firefox ESR below 115.34 and 140.9, and Thunderbird below 149 and 140.9. This vulnerability allows for remote exploitation with low attack complexity (AV:N/AC:L), potentially leading to a complete denial of service (A:H) on affected systems. Currently, there is no indication of active exploitation, public exploit code availability (e.g., Metasploit, ExploitDB), or widespread community discussion beyond vendor security advisories.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 115.34.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 149.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
>= 128.0, < 140.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.