CVE-2026-12297
Received
Received - Intake
Sandbox Escape in Firefox Due to Boundary Condition Error
Publication date: 2026-06-16
Last updated on: 2026-06-16
Assigner: Mozilla Corporation
Description
Description
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mozilla | firefox | 152 |
| mozilla | firefox_esr | 140.12 |
| mozilla | firefox_esr | 115.37 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |