Executive brief
A critical security vulnerability has been identified in the Mozilla Firefox web browser's Profile Backup feature. This flaw allows a malicious website to break out of the browser's security sandbox, which is designed to keep web content isolated from the rest of the computer. If exploited, an attacker could gain unauthorized access to the underlying operating system, potentially leading to the theft of sensitive files or the installation of malware.
Technical details
A sandbox escape vulnerability exists within the Profile Backup component of Mozilla Firefox. While specific technical root causes are restricted in the associated bug reports, the flaw allows a process running within the content sandbox to bypass security boundaries and execute code with the privileges of the parent process or the local user. This is typically achieved by exploiting logic errors or memory corruption within the backup routine to interact with restricted system resources. An attacker could leverage this by enticing a user to visit a malicious webpage, leading to full system compromise. The issue is resolved in Firefox version 150.0.3.
Affected products
- Mozilla Firefox Fixed in 150.0.3
Timeline
- 2026-05-12: disclosed
- 2026-05-12: patched: Fixed in Firefox 150.0.3
- 2026-05-12: advisory