Junglewise Threat Intelligence

CVE-2026-12295: Mozilla Firefox sandbox escape in DOM: Navigation

CVE-2026-12295 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability exists in the Firefox web browser's navigation component. This flaw could allow a malicious website to break out of the browser's security sandbox, which is designed to isolate web content from the rest of the computer. If successfully exploited, an attacker could potentially gain unauthorized access to the underlying operating system or user data.

Technical details

A sandbox escape vulnerability was identified in the DOM: Navigation component of Mozilla Firefox. The vulnerability allows an attacker to bypass the security sandbox, which is a critical layer of defense that restricts the browser's access to system resources. While specific root cause details are restricted in the associated Bugzilla report (Bug 2040160), the flaw is classified as a sandbox escape reachable via web content. An attacker could exploit this to execute code outside of the restricted browser process. The issue is resolved in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Firefox ESR < 140.12, < 115.37

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched
  • 2026-06-16: advisory

References

Related threats