CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.
Other sources
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 147 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.7 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 147 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.7 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 147 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.7
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0878?
CVE-2026-0878 is a critical vulnerability that allows for a sandbox escape in affected versions of Firefox and Firefox ESR.
How do I fix CVE-2026-0878?
To mitigate CVE-2026-0878, users should update to Firefox version 147 or Firefox ESR version 140.7 or later.
Which versions of Firefox are affected by CVE-2026-0878?
CVE-2026-0878 affects Firefox versions prior to 147 and Firefox ESR versions prior to 140.7.
What components are involved in CVE-2026-0878?
CVE-2026-0878 is related to a vulnerability in the Graphics: CanvasWebGL component.
Is CVE-2026-0878 an exploit that can be actively targeted?
Yes, CVE-2026-0878 is an exploit that can be actively targeted due to its nature as a sandbox escape vulnerability.