LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-11708: Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-11708 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.

CVE-2019-11708 is a sandbox escape vulnerability in Mozilla Firefox and Thunderbird that can lead to remote code execution. It matters because a successful escape can let an attacker break out of the browser or mail client's restricted environment and run code with the privileges of the user, increasing the impact of any initial compromise through web content or email.

CISA describes it as a sandbox escape that could result in remote code execution. Defenders should treat it as a high-priority client-side risk on systems where these applications are installed and used to handle untrusted content. Confirm all version and configuration details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In products that rely on a sandbox to isolate untrusted content—such as web pages in Firefox or message content in Thunderbird—insufficient validation of input can allow crafted content to influence behavior outside the intended isolation boundary.

An attacker who can deliver malicious content (for example via a web page or email) may abuse the flawed validation path to escape the sandbox. Once outside the sandbox, the attacker can achieve remote code execution in the context of the application process. Exact exploit mechanics are not detailed in the provided facts; treat any public proof-of-concept claims cautiously and verify technical specifics only against the official Mozilla advisory.

Am I affected? How to find it in your systems

Mozilla Firefox and Thunderbird are common on end-user workstations, developer machines, and some shared or kiosk systems. They may also appear in virtual desktop infrastructure or managed browser deployments.

How to remediate

Patch first. Apply the updates released by Mozilla for Firefox and Thunderbird exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Reduce risk with compensating controls until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to endpoint compromise and subsequent data exposure. Known ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected hosts, preserve volatile evidence, and follow your incident-response process. As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMozilla · Firefox and Thunderbird
WeaknessCWE-20
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities