
DEEP DIVE — CVE-2026-75874: sandbox escape in the Remote Settings client of Firefox and Thunderbird, fixed in 154. Feeds carry CVSS 10.0; Mozilla rates it high and the bug report is still restricted. Quick check: open about:support and read the Version row. https://t.co/NkcTQLALaD
Post summary
The tweet details CVE‑2026‑75874—a sandbox escape in Firefox/Thunderbird’s Remote Settings client with a CVSS of 10.0, patched in version 154, but the bug report remains restricted.

