CVE-2026-7321 PUBLISHED

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component

Assigner: mozilla
Reserved: 28.04.2026 Published: 28.04.2026 Updated: 29.04.2026

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, and Firefox ESR 140.10.1.

Product Status

Vendor Mozilla
Product Firefox
Versions
  • unaffected from 140.10.1 to 140.* (incl.)
  • unaffected from 150 to * (incl.)
Vendor Mozilla
Product Thunderbird
Versions
  • unaffected from 150 to * (incl.)

Credits

  • The Mozilla Fuzzing Team

References