All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-4725
CRITICALpublished 2026-03-24 13:16 UTC · 5 months ago · modified 2026-06-17 10:57 UTC
10.0
CVSS / 10
// description
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
// weaknesses (CWE)
- CWE-416