CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-12295

Critical · CVSS 9.6

Firefox / Thunderbird — Sandbox escape via DOM Navigation component (CWE-693: Protection Mechanism Failure)

CVSS
9.6
nvd
EPSS
0.39%
31th pct
KEV
No
Class
other
CWE-693, CWE-653

Description

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Search profile — drives PoC discovery

Symbols DOMNavigationsandbox escapemfsa2026-57mfsa2026-58mfsa2026-59mfsa2026-60bugzilla 2040160
Keywords CVE-2026-12295Firefox sandbox escapeDOM Navigation sandboxFirefox 152 sandbox escapeFirefox ESR 140.12Firefox ESR 115.37Thunderbird 152 sandbox escapemfsa2026-57mfsa2026-58mfsa2026-59mfsa2026-60bug 2040160 Mozilla
Versions: Firefox < 152, Firefox ESR < 140.12, Firefox ESR < 115.37, Thunderbird < 152, Thunderbird < 140.12

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z