PT-2026-35735 · Mozilla+2 · Thunderbird+4

·

CVE-2026-7321

·

Published

2026-04-28

·

Updated

2026-06-29

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 150 Thunderbird versions prior to 150 Firefox ESR versions prior to 140.10.1
Description A sandbox escape exists in the WebRTC: Networking component caused by incorrect boundary conditions. A sandbox is a security mechanism used to separate running programs from the rest of the system to prevent malicious code from accessing sensitive data or resources.
Recommendations Update Firefox to version 150. Update Thunderbird to version 150. Update Firefox ESR to version 140.10.1.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19153
ALSA-2026:19157
ALSA-2026:19348
ALSA-2026:19370
ALSA-2026:19588
ALSA-2026:20586
BDU:2026-09781
CVE-2026-7321
OESA-2026-2132
OESA-2026-2133
OESA-2026-2134
OESA-2026-2246
OESA-2026-2275
OPENSUSE-SU-2026:10661-1
OPENSUSE-SU-2026:10687-1
OPENSUSE-SU-2026:21168-1
RHSA-2026:19153
RHSA-2026:19157
RHSA-2026:19348
RHSA-2026:19370
RHSA-2026:19588
RHSA-2026:20586
RHSA-2026:21743
RHSA-2026:22847
RHSA-2026:24345
RHSA-2026:24717
RHSA-2026:24718
RHSA-2026:24719
RHSA-2026:24721
RHSA-2026:24844
RHSA-2026:24846
RHSA-2026:25014

Affected Products

Firefox
Firefox Esr
Red Os
Rocky Linux
Thunderbird