CVE-2026-8401
Critical · CVSS 9.8Mozilla Firefox / Thunderbird — Sandbox escape via Profile Backup component (Protection Mechanism Failure / Insufficient Compartmentalization)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-693, CWE-653
Description
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
Search profile — drives PoC discovery
Symbols Profile Backupsandbox escapemfsa2026-45mfsa2026-47mfsa2026-48mfsa2026-51bug 2038679CWE-693CWE-653
Keywords CVE-2026-8401Firefox sandbox escapeProfile Backup sandboxFirefox 150.0.3 sandboxFirefox ESR 115.36Firefox ESR 140.11Thunderbird 140.11 sandbox escapemfsa2026-45mfsa2026-47mfsa2026-48mfsa2026-51bugzilla 2038679Firefox Profile Backup vulnerabilityFirefox sandbox bypass PoC
Versions: Firefox < 150.0.3, Firefox ESR < 115.36, Firefox ESR < 140.11, Thunderbird < 140.11
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2038679
- https://www.mozilla.org/security/advisories/mfsa2026-45/
- https://www.mozilla.org/security/advisories/mfsa2026-47/
- https://www.mozilla.org/security/advisories/mfsa2026-48/
- https://www.mozilla.org/security/advisories/mfsa2026-51/
- https://access.redhat.com/errata/RHSA-2026:21378
- https://access.redhat.com/errata/RHSA-2026:21380
- https://access.redhat.com/errata/RHSA-2026:21381
- https://access.redhat.com/errata/RHSA-2026:21382
- https://access.redhat.com/errata/RHSA-2026:22325
- https://access.redhat.com/errata/RHSA-2026:22643
- https://access.redhat.com/errata/RHSA-2026:26174
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z