Junglewise Threat Intelligence

CVE-2026-8945: Mozilla Firefox for Android sandbox escape

CVE-2026-8945 · Severity: info · CVSS 8.8 · Published 2026-05-19

Technologies: Mozilla Firefox Focus for Android, Mozilla Firefox for Android. Vendors: Mozilla.

Executive brief

A security vulnerability has been identified in the Android versions of the Firefox and Firefox Focus web browsers. This flaw allows a malicious website to break out of the browser's security sandbox, which is designed to keep web content isolated from the rest of the device. If exploited, an attacker could potentially gain unauthorized access to the underlying mobile operating system or sensitive user data.

Technical details

A sandbox escape vulnerability exists in Firefox and Firefox Focus for Android. While specific root cause details are restricted in the associated Bugzilla report (Bug 2003171), the vulnerability allows content running within the browser's restricted sandbox environment to bypass these protections and interact with the broader Android system. An attacker would typically exploit this by enticing a user to visit a specially crafted webpage. Successful exploitation could lead to arbitrary code execution outside of the browser process. The issue is addressed in Firefox 151.

Affected products

  • Mozilla Firefox for Android < 151
  • Mozilla Firefox Focus for Android < 151

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats