Junglewise Threat Intelligence

CVE-2026-8953: Mozilla Firefox sandbox escape in Disability Access APIs

CVE-2026-8953 · Severity: info · Published 2026-05-19

Technologies: Mozilla FirefoxBase, Mozilla Firefox ESR. Vendors: Mozilla.

Executive brief

A vulnerability in the Firefox web browser could allow an attacker to bypass security protections designed to isolate the browser from the rest of the computer system. This component is responsible for accessibility features that help users with disabilities interact with the web. If exploited, an attacker could potentially gain unauthorized access to the underlying operating system or user data beyond the browser's normal restrictions.

Technical details

A use-after-free vulnerability exists in the Disability Access APIs component of Mozilla Firefox. The flaw occurs when the browser continues to use a memory address after it has been freed, which can be manipulated to achieve a sandbox escape. An attacker could exploit this by enticing a user to visit a specially crafted website, potentially allowing code execution outside of the browser's sandboxed process. The vulnerability is fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 115.36, < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats