CVE-2026-12296
Critical · CVSS 9.6Mozilla Firefox / Thunderbird — Sandbox escape in Process Sandboxing component
- CVSS
- 9.6
- nvd
- EPSS
- 0.39%
- 31th pct
- KEV
- No
- Class
- other
- CWE-693, CWE-403
Description
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
Search profile — drives PoC discovery
Symbols Security: Process Sandboxingmfsa2026-57mfsa2026-58mfsa2026-60mfsa2026-61bug 2040515
Keywords CVE-2026-12296Firefox sandbox escapeThunderbird sandbox escapeProcess Sandboxing bypassFirefox 152 sandboxFirefox ESR 140.12Thunderbird 152Thunderbird 140.12mfsa2026-57CWE-693 Firefoxbugzilla 2040515
Versions: Firefox < 152, Firefox ESR < 140.12, Thunderbird < 152, Thunderbird ESR < 140.12
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2040515
- https://www.mozilla.org/security/advisories/mfsa2026-57/
- https://www.mozilla.org/security/advisories/mfsa2026-58/
- https://www.mozilla.org/security/advisories/mfsa2026-60/
- https://www.mozilla.org/security/advisories/mfsa2026-61/
- https://access.redhat.com/errata/RHSA-2026:27717
- https://access.redhat.com/errata/RHSA-2026:27733
- https://access.redhat.com/errata/RHSA-2026:27734
- https://access.redhat.com/errata/RHSA-2026:29940
- https://access.redhat.com/errata/RHSA-2026:30846
- https://access.redhat.com/errata/RHSA-2026:33445
- https://access.redhat.com/errata/RHSA-2026:36100
Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z