CVE-2026-8959
9.6 CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Published: 2026-05-19 · Last updated: 2026-05-20
Severity and scoring
- CVSS
- 9.6 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- CWE
- CWE-119, CWE-20, CWE-693
Affected products
| Vendor | Product |
|---|---|
| mozilla | firefox, thunderbird |
Description
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-8959
- [Other]https://bugzilla.mozilla.org/show_bug.cgi?id=2034754
- [Vendor advisory]https://www.mozilla.org/security/advisories/mfsa2026-46/
- [Vendor advisory]https://www.mozilla.org/security/advisories/mfsa2026-48/
- [Vendor advisory]https://www.mozilla.org/security/advisories/mfsa2026-50/
- [Vendor advisory]https://www.mozilla.org/security/advisories/mfsa2026-51/
Related CVEs
Same vendor
- CVE-2026-10702 — JIT miscompilation in the JavaScript Engine: JIT component (4.3 MEDIUM)
- CVE-2026-10701 — Incorrect boundary conditions in the Graphics: Text component (7.5 HIGH)
- CVE-2026-9309 — Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata (5.4 MEDIUM)
- CVE-2026-9308 — Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders (5.4 MEDIUM)
- CVE-2026-9078 — Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI ... (5.4 MEDIUM)
Same CWE
- CVE-2026-47370 — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain... (9.9 CRITICAL)
- CVE-2026-47369 — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain... (9.9 CRITICAL)
- CVE-2026-47367 — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Ent... (9.9 CRITICAL)
- CVE-2026-12034 — Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote at... (8.3 HIGH)
- CVE-2026-12031 — Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised t... (8.3 HIGH)