Security Advisory

CVE-2023-6860

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-12-19 13:38:40
Last updated 2025-02-13 17:26:36
Assigner mozilla
State PUBLISHED

Description

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.