Sandbox Escape Vulnerability in Firefox WebRTC Networking Component
CVE-2026-7321

9.6CRITICAL

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-7321?

A vulnerability exists in the WebRTC Networking component of Firefox that could allow a sandbox escape due to incorrect boundary conditions. This issue potentially exposes users to various security risks. Mozilla has released a fix in version 140.10.1 of Firefox ESR to address this vulnerability. It is crucial for users to update their software to maintain security and ensure the integrity of their browsing experience.

Affected Version(s)

Firefox 140.10.1

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bugmon
.