CVE-2026-0881: Sandbox escape in the Messaging System component
Sandbox escape in the Messaging System component. This vulnerability affects Firefox < 147.
Other sources
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 147 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 147 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 147
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0881?
CVE-2026-0881 is considered a high-severity vulnerability due to its potential for sandbox escape.
How do I fix CVE-2026-0881?
To fix CVE-2026-0881, users should upgrade to Firefox version 147 or later.
What versions of Firefox are affected by CVE-2026-0881?
CVE-2026-0881 affects all versions of Firefox prior to version 147.
What impact does CVE-2026-0881 have on users?
CVE-2026-0881 allows attackers to escape the browser sandbox, potentially compromising user data and system security.
Is there a workaround for CVE-2026-0881?
There are no recommended workarounds for CVE-2026-0881; the best protection is to update to the latest version of Firefox.