Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:0667 cve-icon
https://access.redhat.com/errata/RHSA-2026:0694 cve-icon
https://access.redhat.com/errata/RHSA-2026:0924 cve-icon
https://access.redhat.com/errata/RHSA-2026:1320 cve-icon
https://access.redhat.com/errata/RHSA-2026:1413 cve-icon
https://access.redhat.com/errata/RHSA-2026:1414 cve-icon
https://access.redhat.com/errata/RHSA-2026:1415 cve-icon
https://access.redhat.com/errata/RHSA-2026:1461 cve-icon
https://access.redhat.com/errata/RHSA-2026:1462 cve-icon
https://access.redhat.com/errata/RHSA-2026:1471 cve-icon
https://access.redhat.com/errata/RHSA-2026:1487 cve-icon
https://access.redhat.com/errata/RHSA-2026:2041 cve-icon
https://access.redhat.com/errata/RHSA-2026:2043 cve-icon
https://access.redhat.com/errata/RHSA-2026:2044 cve-icon
https://access.redhat.com/errata/RHSA-2026:2047 cve-icon
https://access.redhat.com/errata/RHSA-2026:2069 cve-icon
https://access.redhat.com/errata/RHSA-2026:2070 cve-icon
https://access.redhat.com/errata/RHSA-2026:2073 cve-icon
https://access.redhat.com/errata/RHSA-2026:2074 cve-icon
https://access.redhat.com/errata/RHSA-2026:2220 cve-icon
https://access.redhat.com/errata/RHSA-2026:2231 cve-icon
https://access.redhat.com/errata/RHSA-2026:2271 cve-icon
https://access.redhat.com/errata/RHSA-2026:2286 cve-icon
https://access.redhat.com/security/cve/CVE-2026-0880 cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=2005014 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2428975 cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-0880 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0880.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-0880 cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-01/ cve-icon cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-02/ cve-icon cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-03/ cve-icon cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-03/#CVE-2026-0880 cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-04/ cve-icon cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-05/ cve-icon cve-icon
History

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to integer overflow in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
Vendors & Products Mozilla thunderbird

Thu, 15 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to integer overflow in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, and Firefox ESR < 140.7. Sandbox escape due to integer overflow in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
References

Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Mozilla firefox Esr
Vendors & Products Mozilla
Mozilla firefox
Mozilla firefox Esr

Wed, 14 Jan 2026 00:15:00 +0000


Tue, 13 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Jan 2026 14:00:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to integer overflow in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, and Firefox ESR < 140.7.
Title Sandbox escape due to integer overflow in the Graphics component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2026-01-13T13:30:54.679Z

Updated: 2026-07-15T01:23:52.068Z

Reserved: 2026-01-13T13:30:54.411Z

Link: CVE-2026-0880

cve-icon Vulnrichment

Updated: 2026-07-01T12:05:13.451Z

cve-icon NVD

Status : Modified

Published: 2026-01-13T14:16:38.557

Modified: 2026-07-15T02:17:58.990

Link: CVE-2026-0880

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-13T13:30:54Z

Links: CVE-2026-0880 - Bugzilla