Executive brief
Mozilla Firefox is a popular web browser used to access the internet and internal web applications. A vulnerability in the browser's networking component could allow a malicious website to bypass security 'sandbox' protections that normally isolate web content from the rest of the computer. If successfully exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or sensitive user data.
Technical details
A sandbox escape vulnerability exists in the Networking component of Mozilla Firefox due to incorrect boundary conditions. The flaw allows an attacker to bypass the process sandboxing protections that isolate the browser's content process from the host operating system. While specific technical details are restricted in the associated Bugzilla report, the vulnerability is triggered during network operations and can lead to a full compromise of the user's system if combined with a separate content process vulnerability. The issue is resolved in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
- Mozilla Firefox ESR < 115.37
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory