Executive brief
Mozilla Firefox is a widely used web browser. A vulnerability in its security sandboxing component could allow a malicious website to bypass security restrictions and access sensitive information from the user's system. This could lead to the exposure of private data or allow an attacker to gain more control over the affected device than the browser normally permits.
Technical details
A vulnerability exists in the 'Security: Process Sandboxing' component of Mozilla Firefox. The flaw allows for both information disclosure and a sandbox escape, potentially enabling a compromised content process to interact with the host system or access data outside of its intended boundaries. The vulnerability is triggered when a user visits a malicious or compromised webpage. Mozilla has addressed this issue in Firefox 152 and Firefox ESR 140.12. Specific root cause details are currently restricted in the associated Bugzilla report (Bug 2040177).
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched