CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.
Other sources
Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox ESR 140.10.1.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.10.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.10.1 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.10.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-7320
- CVE-2026-7321
- CVE-2026-8091
- CVE-2026-7322
- CVE-2026-7323
- CVE-2026-6746
- CVE-2026-6747
- CVE-2026-6748
- CVE-2026-6749
- CVE-2026-6750
- CVE-2026-6751
- CVE-2026-6752
- CVE-2026-6753
- CVE-2026-6754
- CVE-2026-6755
- CVE-2026-6757
- CVE-2026-6758
- CVE-2026-6759
- CVE-2026-6760
- CVE-2026-6761
- CVE-2026-6762
- CVE-2026-6763
- CVE-2026-6764
- CVE-2026-6765
- CVE-2026-6766
- CVE-2026-6767
- CVE-2026-6768
- CVE-2026-6769
- CVE-2026-6770
- CVE-2026-6771
- CVE-2026-6772
- CVE-2026-6773
- CVE-2026-6774
- CVE-2026-6775
- CVE-2026-6776
- CVE-2026-6777
- CVE-2026-6778
- CVE-2026-6779
- CVE-2026-6780
- CVE-2026-6781
- CVE-2026-6782
- CVE-2026-6783
- CVE-2026-6784
- CVE-2026-6785
- CVE-2026-6786
- CVE-2026-6756
Frequently Asked Questions
What is the severity of CVE-2026-7321?
CVE-2026-7321 has been classified with a high severity rating due to the potential for sandbox escape.
How do I fix CVE-2026-7321?
To mitigate CVE-2026-7321, update to Firefox or Thunderbird version 150 or Firefox ESR version 140.10.1 or later.
What components are affected by CVE-2026-7321?
CVE-2026-7321 affects the WebRTC: Networking component in Mozilla products.
Is CVE-2026-7321 applicable to older versions of Mozilla Firefox?
Yes, CVE-2026-7321 is applicable to versions prior to Firefox and Thunderbird 150 and Firefox ESR 140.10.1.
What could be the impact of exploiting CVE-2026-7321?
Exploiting CVE-2026-7321 could allow attackers to escape the sandbox, potentially gaining unauthorized access to system resources.