<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-4687 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-4687/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 24 Mar 2026 13:16:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-4687/feed.xml" rel="self" type="application/rss+xml"/><item><title>Firefox and Thunderbird Sandbox Escape Vulnerability (CVE-2026-4687)</title><link>https://feed.craftedsignal.io/briefs/2026-03-firefox-sandbox-escape/</link><pubDate>Tue, 24 Mar 2026 13:16:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-firefox-sandbox-escape/</guid><description>CVE-2026-4687 is a sandbox escape vulnerability in Firefox and Thunderbird due to incorrect boundary conditions in the Telemetry component, potentially allowing an attacker to execute arbitrary code outside the sandbox.</description><content:encoded>&lt;p>CVE-2026-4687 is a critical sandbox escape vulnerability affecting Mozilla Firefox and Thunderbird. The vulnerability stems from incorrect boundary conditions within the Telemetry component. Specifically, Firefox versions prior to 149, Firefox ESR versions prior to 115.34 and 140.9, and Thunderbird versions prior to 149 and 140.9 are affected. Successful exploitation could allow an attacker to bypass the intended security restrictions of the sandbox environment and potentially execute arbitrary…&lt;/p>
</content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>sandbox-escape</category><category>firefox</category><category>thunderbird</category><category>cve-2026-4687</category></item></channel></rss>