Executive brief
A security vulnerability in the Firefox web browser could allow a malicious website to bypass the browser's security sandbox. The sandbox is a critical defense mechanism designed to prevent web content from interacting with the underlying operating system or accessing private files. If exploited, an attacker could potentially gain unauthorized access to the user's computer or sensitive data.
Technical details
A sandbox escape vulnerability exists in the DOM: Workers component of Mozilla Firefox. The flaw allows content running within a worker context to bypass the process sandbox, which is intended to isolate web content from the rest of the system. While specific root cause details are restricted in the associated Bugzilla report, the vulnerability is classified as high impact and could lead to a full compromise of the host environment if combined with other exploits. The issue is resolved in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12, < 115.37
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory