CVE-2023-6860: Medium severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
The VideoBridge allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-54/#CVE-2023-6860
— Red Hat
The VideoBridge allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
— MITRE
The VideoBridge allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6860?
CVE-2023-6860 is classified as a high severity vulnerability, allowing potential sandbox escape.
How do I fix CVE-2023-6860?
To address CVE-2023-6860, update to the latest versions of affected software such as Firefox ESR 115.6, Firefox 121, or Thunderbird 115.6.
Which versions are affected by CVE-2023-6860?
CVE-2023-6860 affects Firefox ESR versions prior to 115.6 and Firefox versions prior to 121, along with Thunderbird versions prior to 115.6.
What is the impact of CVE-2023-6860?
Exploiting CVE-2023-6860 could allow an attacker to escape the sandbox and potentially access unauthorized resources.
Is there a known exploit for CVE-2023-6860?
As of now, there are no public reports of active exploits targeting CVE-2023-6860.