Sandbox Escape Vulnerability in Firefox by Mozilla
CVE-2026-12296

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-12296?

A critical vulnerability has been identified in the Process Sandboxing component of Firefox, allowing an attacker to escape the isolated environment established for secure operations. This flaw highlights a significant risk, as it can potentially enable unauthorized access to sensitive information and system resources. Users of Firefox 152 and Firefox ESR 140.12 are advised to update their software to mitigate the risk associated with this vulnerability.

Affected Version(s)

Firefox 140.12

Firefox 152

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaqoub Aldurayhim
.