Executive brief
Mozilla Firefox is a popular web browser used to access the internet. A vulnerability in its security sandboxing component could allow a malicious website to bypass security restrictions and access information from the user's computer that should be protected. This could lead to the exposure of sensitive data or allow an attacker to gain more control over the system than the browser normally permits.
Technical details
An information disclosure and sandbox escape vulnerability exists in the 'Security: Process Sandboxing' component of Mozilla Firefox. While specific technical root causes are restricted in the associated bug reports, the flaw allows an attacker to bypass the process sandbox, potentially leading to unauthorized access to sensitive data or elevated privileges on the host system. The vulnerability is triggered via web content and was addressed by improving boundary checks or logic within the sandboxing mechanism. Users should update to Firefox 152 or Firefox ESR 140.12 to mitigate this risk.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched