Executive brief
Mozilla Firefox is a widely used web browser. A security flaw in the browser's site isolation mechanism could allow a malicious website to bypass security boundaries that normally keep data from different websites separate. While exploit code is publicly available, there are no reports of this being used in active attacks, and users should update to the latest version to remain protected.
Technical details
A vulnerability exists in the DOM: Navigation component of Mozilla Firefox related to site isolation. The flaw could allow a malicious site to bypass security boundaries intended to isolate web content from different origins. The attack vector is network-based and requires a user to visit a specially crafted website (User Interaction). Although the reported CVSS score is 5.4 (Medium), Mozilla's internal advisory classifies the impact as Critical. Public exploit code is available, but no active exploitation has been observed. The issue is resolved in Firefox 152.0.6.
Affected products
- Mozilla Firefox < 152.0.6
Timeline
- 2026-07-14: disclosed
- 2026-07-14: patched: Fixed in Firefox 152.0.6
- 2026-07-14: advisory