Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
The use-after-free vulnerability (CWE-416) involves referencing a memory area that has already been freed within the Disability Access APIs component. This error allows an attacker to manipulate memory structures of the browser or email client process in a way that enables escaping the isolated execution environment (sandbox). Since the attack vector is network-based, it requires no user interaction or special privileges, and the scope of the attack extends beyond the vulnerable component (S:C), so the impact can affect the entire operating system.
An attacker can escape the browser or email client sandbox, gaining the ability to execute arbitrary code with the privileges of the host process, resulting in complete compromise of system confidentiality, integrity, and availability.
Software must be updated immediately to Firefox 149, Firefox ESR 140.9, Thunderbird 149, or Thunderbird 140.9, in which the vulnerability has been fixed. Patches are available directly from the manufacturer according to references in Mozilla advisories (mfsa2026-20, mfsa2026-22, mfsa2026-23, mfsa2026-24).
Mozilla Firefox versions prior to 149, Mozilla Firefox ESR versions prior to 140.9, Mozilla Thunderbird versions prior to 149, and Mozilla Thunderbird ESR versions prior to 140.9.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HMozilla Firefox
APPMozilla< 140.9.0< 149.0
Related vulnerabilities
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open
RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...