CVE-2026-4690 describes a high-severity sandbox escape vulnerability stemming from incorrect boundary conditions and an integer overflow within the XPCOM component of Mozilla Firefox and Thunderbird. Affecting multiple versions, including Firefox < 149 and Thunderbird < 149, this flaw carries a CVSS score of 8.6 (High). It can be exploited remotely over the network with low complexity and no user interaction, potentially leading to a high impact on system availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not present on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 115.34.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 149.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
>= 128.0, < 140.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.