Junglewise Threat Intelligence

CVE-2026-12313: Mozilla Firefox sandbox escape in Process Sandboxing

CVE-2026-12313 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a popular web browser used to access the internet. A vulnerability in its security sandboxing component could allow a malicious website to bypass security restrictions and access information from the user's computer that should be protected. This could lead to the exposure of sensitive data or allow an attacker to gain more control over the system than the browser normally permits.

Technical details

An information disclosure and sandbox escape vulnerability exists in the 'Security: Process Sandboxing' component of Mozilla Firefox. While specific technical root causes are restricted in the associated bug reports, the flaw allows an attacker to bypass the process sandbox, potentially leading to unauthorized access to sensitive data or elevated privileges on the host system. The vulnerability is triggered via web content and was addressed by improving boundary checks or logic within the sandboxing mechanism. Users should update to Firefox 152 or Firefox ESR 140.12 to mitigate this risk.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Firefox ESR < 140.12

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched

References

Related threats