Executive brief
A vulnerability in the Firefox web browser's security sandbox could allow a malicious website to bypass protective barriers and access sensitive information. The sandbox is designed to isolate web content from the rest of the computer; a failure in this component could lead to unauthorized data access or broader system compromise. Users should update to the latest version of Firefox to ensure these protections are active.
Technical details
A vulnerability exists in the 'Security: Process Sandboxing' component of Mozilla Firefox. The flaw allows for both information disclosure and a sandbox escape, potentially enabling a compromised content process to interact with the host operating system or other processes in ways that should be restricted. While specific root cause details (such as the exact code-level bug) are restricted in the associated Bugzilla report, the impact is classified as moderate by Mozilla. The vulnerability is addressed in Firefox 151 and Firefox ESR 140.11. Exploitation typically requires a user to visit a malicious or compromised website.
Affected products
- Mozilla Firefox < 151
- Mozilla Firefox ESR < 140.11
Timeline
- 2026-05-19: disclosed
- 2026-05-19: patched
- 2026-05-19: advisory