Description
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2.
Published: 2026-08-18
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The most recent security advisory clarifies that the Remote Settings Client component contains a sandbox escape flaw (CWE-653, CWE-693). The description does not specify how the flaw is triggered, but it is inferred that malicious remote settings data processed by the component could allow an attacker to break out of the browser’s process sandbox and execute code with the client’s privileges. If successfully exploited, this would compromise confidentiality, integrity, and availability of the victim’s machine, representing a remote code execution path.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird users running versions earlier than 154 are vulnerable. The Remote Settings Client is part of the core components delivered by Mozilla, affecting all installations of Firefox and Thunderbird that have not yet been updated to the patched build.

Risk and Exploitability

The CVSS score is 10, indicating a critical level of severity. The EPSS score of < 1% indicates a very low exploitation probability. This vulnerability is not listed in CISA’s KEV catalog, which means there is no confirmed widespread exploitation yet, but the potential for serious impact remains. Based on the description, it is inferred that the likely attack vector is through remotely delivered settings or configuration data, which can be controlled by a malicious web server or compromised network infrastructure. The CVE description does not specify whether authentication or local access is required to trigger the flaw.

Generated by OpenCVE AI on September 2, 2026 at 06:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply vendor patch v154 or later
  • Configure the network or policy engine to block or restrict access to Mozilla’s remote settings service
  • Enforce browser update channels to automatically install security updates

Generated by OpenCVE AI on September 2, 2026 at 06:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4770-1 firefox-esr security update
Debian DLA Debian DLA DLA-4775-1 thunderbird security update
Debian DSA Debian DSA DSA-6481-1 firefox-esr security update
Debian DSA Debian DSA DSA-6483-1 thunderbird security update
History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 140.15, and Thunderbird 153.2.
References

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
References

Fri, 21 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264
CWE-284

Fri, 21 Aug 2026 12:15:00 +0000


Wed, 19 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154. Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
References

Tue, 18 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-264
CWE-284
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154.
Title Sandbox escape in the Remote Settings Client component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T21:44:07.705Z

Reserved: 2026-08-18T12:23:35.313Z

Link: CVE-2026-75874

cve-icon Vulnrichment

Updated: 2026-08-18T19:23:39.591Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T13:17:43.500

Modified: 2026-09-01T22:17:12.863

Link: CVE-2026-75874

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-18T12:23:35Z

Links: CVE-2026-75874 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T07:00:13Z

Weaknesses
  • CWE-653

    Improper Isolation or Compartmentalization

  • CWE-693

    Protection Mechanism Failure