A critical vulnerability classified as a sandbox escape has been identified in the Remote Settings Client component, impacting Mozilla Firefox, Thunderbird, and the associated library. This flaw enables attackers to bypass security restrictions and execute arbitrary code, posing a severe risk to system integrity. The vulnerability affects all versions prior to Firefox 154 and Thunderbird 154. Given its CVSS score of 10.0, this is a high-severity issue with potential for remote code execution. Users of affected software are strongly advised to update to the patched versions immediately. Organizations should prioritize applying this update to mitigate exploitation risks, as unpatched systems remain exposed to attack vectors leveraging this flaw. No workarounds are available aside from applying the official patches. Security teams are urged to monitor for exploitation attempts and ensure compliance with the latest software updates.
CRITICAL
CVSS 10.0
CVE-2026-75874
2026-08-21
Critical Sandbox Escape Vulnerability in Remote Settings Client (CVE-2026-75874)
A critical sandbox escape vulnerability in the Remote Settings Client component affects Firefox, Thunderbird, and related libraries. This issue allows arbitrary code execution and was resolved in version 154 of affected software.