CVE-2025-13026
BaseFortify
Publication date: 2025-11-11
Last updated on: 2026-04-13
Assigner: Mozilla Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | to 145.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-703 | The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
This vulnerability can allow an attacker to escape the sandbox environment in Firefox, potentially leading to execution of arbitrary code or access to sensitive information outside the intended restricted environment, increasing the risk of system compromise.
Can you explain this vulnerability to me?
This vulnerability is a sandbox escape caused by incorrect boundary conditions in the Graphics: WebGPU component of Firefox versions before 145. It allows an attacker to break out of the restricted environment (sandbox) intended to isolate processes, potentially leading to unauthorized actions.