CVE-2022-46872: Mozilla Firefox

High severity, CVSS 8.6. EPSS: 0.8% chance of exploitation in the next 30 days.

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

Affected products

  • Mozilla Firefox: before 108.0 (fixed in 108.0)
  • Mozilla Firefox ESR: before 102.6 (fixed in 102.6)
  • Mozilla Thunderbird: before 102.6 (fixed in 102.6)

Published 2022-12-22. Last modified 2026-06-17.