Information Disclosure in Firefox Security Process Sandboxing by Mozilla
CVE-2026-8958

8.6HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 May 2026

What is CVE-2026-8958?

This vulnerability involves an information disclosure and sandbox escape within the Security: Process Sandboxing component of Mozilla Firefox. A flaw in this component could allow an attacker to extract sensitive information from the browser's secure sandbox environment. The issue has been remediated in Firefox version 151 and Firefox Extended Support Release (ESR) version 140.11, highlighting the importance of updating to the latest versions to mitigate potential risks.

Affected Version(s)

Firefox 140.11

Firefox 151

Thunderbird 140.11

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaqoub Aldurayhim
.