CVE-2026-4689

Updated on 24 Mar 2026

Severity

10.0 Critical severity

Details

CVSS score
10.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Overview

About vulnerability

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Details

Affected product:
AlmaLinux 9.2 ESU
Affected packages:
thunderbird @ 115.4.1

Fixes