Sandbox Escape Vulnerability in Mozilla Firefox and ESR Versions
CVE-2026-12297

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-12297?

A potential sandbox escape was discovered in the Networking component of Mozilla Firefox, caused by incorrect boundary conditions. This vulnerability allows for unintended data leakage and could enable attackers to execute certain operations outside the rigorously defined sandbox environment. Mozilla has addressed this issue by releasing updates in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37, enhancing the security integrity of the affected products.

Affected Version(s)

Firefox 115.37

Firefox 140.12

Firefox 152

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zx
.