#VU124293 Out-of-bounds write in Mozilla products - CVE-2026-4687

 

#VU124293 Out-of-bounds write in Mozilla products - CVE-2026-4687

Published: March 24, 2026


Vulnerability identifier: #VU124293
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-4687
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Firefox for Android
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions in the Telemetry component when handling telemetry data. A remote attacker can trick the victim into visiting a specially crafted website and escape the sandbox.

Successful exploitation could allow an attacker to execute code outside the browser's sandbox with elevated privileges.


Remediation

Install security update from vendor's website.

External links