CVE-2026-4692
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
- Affected products
- Firefox, Firefox Esr, Red Os, Rocky Linux, Thunderbird
- Mozilla Firefox
- < 115.34.0, 149.0, 140.9.0
- Mozilla Thunderbird
- < 140.9.0, 149.0
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-653
- NVD status
- Modified
- Published
- 2026-03-24
CVE-2026-4692 at NVD
2 known exploits for CVE-2026-4692
Proof-of-concept code and exploit modules indexed by Sploitus