CVE-2026-12295
Critical · CVSS 9.6Firefox / Thunderbird — Sandbox escape via DOM Navigation component (CWE-693: Protection Mechanism Failure)
- CVSS
- 9.6
- nvd
- EPSS
- 0.39%
- 31th pct
- KEV
- No
- Class
- other
- CWE-693, CWE-653
Description
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
Search profile — drives PoC discovery
Symbols DOMNavigationsandbox escapemfsa2026-57mfsa2026-58mfsa2026-59mfsa2026-60bugzilla 2040160
Keywords CVE-2026-12295Firefox sandbox escapeDOM Navigation sandboxFirefox 152 sandbox escapeFirefox ESR 140.12Firefox ESR 115.37Thunderbird 152 sandbox escapemfsa2026-57mfsa2026-58mfsa2026-59mfsa2026-60bug 2040160 Mozilla
Versions: Firefox < 152, Firefox ESR < 140.12, Firefox ESR < 115.37, Thunderbird < 152, Thunderbird < 140.12
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 39hiteshsuthar01/OK- needs reviewgh_search
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2040160
- https://www.mozilla.org/security/advisories/mfsa2026-57/
- https://www.mozilla.org/security/advisories/mfsa2026-58/
- https://www.mozilla.org/security/advisories/mfsa2026-59/
- https://www.mozilla.org/security/advisories/mfsa2026-60/
- https://www.mozilla.org/security/advisories/mfsa2026-61/
- https://access.redhat.com/errata/RHSA-2026:27717
- https://access.redhat.com/errata/RHSA-2026:27733
- https://access.redhat.com/errata/RHSA-2026:27734
- https://access.redhat.com/errata/RHSA-2026:29940
- https://access.redhat.com/errata/RHSA-2026:30846
- https://access.redhat.com/errata/RHSA-2026:33445
Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z