Security Advisory

CVE-2026-0878

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-13 13:30:53
Last updated 2026-04-13 13:51:40
Assigner mozilla
State PUBLISHED

Description

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.