Junglewise Threat Intelligence

CVE-2026-12296: Mozilla Firefox sandbox escape in Process Sandboxing

CVE-2026-12296 · Severity: info · CVSS 8.8 · Published 2026-06-16

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability has been identified in the Mozilla Firefox web browser's process sandboxing component. This component is designed to isolate web content from the rest of the computer to prevent malicious websites from causing harm. An exploit could allow a malicious website to 'escape' this isolation, potentially gaining unauthorized access to the user's files or system.

Technical details

A sandbox escape vulnerability exists in the Security: Process Sandboxing component of Mozilla Firefox. The flaw allows an attacker to bypass the security boundaries intended to isolate the browser's content processes from the underlying operating system. While specific root cause details are restricted in the associated bug report, sandbox escapes typically involve flaws in Inter-Process Communication (IPC) or broker services. An attacker could leverage this in conjunction with another vulnerability (such as a memory safety bug) to execute arbitrary code outside of the restricted sandbox environment. The issue is resolved in Firefox 152 and Firefox ESR 140.12.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Firefox ESR < 140.12

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched
  • 2026-06-16: advisory

References

Related threats