


Perceptive Security
SOC/SIEM Consultancy

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149 and Firefox ESR < 140.9.
Published:
23 maart 2026 om 23:00:00
Alert date:
24 maart 2026 om 20:06:33
Source:
nvd.nist.gov
Web Technologies
A use-after-free vulnerability in Firefox's Disability Access APIs component allows sandbox escape. This critical security flaw affects Firefox versions below 149 and Firefox ESR versions below 140.9. The vulnerability is tracked as CVE-2026-4688 and has been assigned a high criticality rating. Mozilla has released security advisories and patches to address this issue. The bug was reported through Mozilla's Bugzilla system and affects multiple Firefox distributions.
Technical details
Mitigation steps:
Affected products:
Firefox
Firefox ESR
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4688
https://bugzilla.mozilla.org/show_bug.cgi?id=2016373
https://www.mozilla.org/security/advisories/mfsa2026-20/
https://www.mozilla.org/security/advisories/mfsa2026-22/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
