CVE-2026-4725Disclosure(mozilla / firefox)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch mozilla firefox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-24); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
firefox

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-24: 3Mentions · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-25: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-25: 103-2403-25
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure3
2026-03-251
Disclosure1
Full discourse4 posts
  • maruomosquit@maru1151157
    Disclosure

    🚨 CVE-2026-4725 (CVSS: 10.0) FirefoxおよびThunderbirdのGraphics: Canvas2Dコンポーネントにおけるuse-after-freeによりサンドボックス回避が可能。Firefox <149およびThunderbird <149に影響。バージョン149以上に更新。 https://maruomosquit.com/vulnerability/CVE-2026-4725/ #脆弱性 #セキュリティ

    Post summary

    A critical use‑after‑free vulnerability (CVE‑2026‑4725) in Firefox and Thunderbird’s Canvas2D component has been disclosed, and users are advised to upgrade to version 149 or newer.

    0002055
    1.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4725 - Critical Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149 and Thunderbird < 149. https://www.thehackerwire.com/vulnerability/CVE-2026-4725/ https://t.co/jMc90UmVyc

    Post summary

    CVE-2026-4725 is a newly disclosed critical vulnerability causing a sandbox escape via a use‑after‑free in Firefox and Thunderbird’s Canvas2D component for versions prior to 149.

    0000050
    145 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4725 Use-After-Free Sandbox Escape in Firefox Canvas2D Before Version 149 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4725

    Post summary

    This brief notice announces CVE-2026-4725, a Use-After-Free sandbox escape in Firefox Canvas2D before version 149, without references to PoC, exploit code, or mitigation.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4725 Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149. https://www.cve.org/CVERecord?id=CVE-2026-4725

    Post summary

    The text announces CVE‑2026‑4725, describing a sandbox escape via use‑after‑free in Firefox’s Canvas2D component, with no PoC, exploit, active exploitation, or patch information provided.

    00000105
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---

Explore more