Mozilla Firefox and Firefox ESR Sandbox Escape Vulnerability

Vulnerability

A sandbox escape vulnerability has been identified in Mozilla Firefox versions prior to 147, as well as in Firefox ESR versions prior to 115.32 and prior to 140.7. This vulnerability arises from incorrect boundary conditions in the Graphics component, which could potentially be exploited to escape the sandbox environment and execute unauthorized actions or access restricted resources.

Impact

Exploitation of this vulnerability allows for a sandbox escape, enabling potentially malicious actions or access to restricted resources that are normally protected by the sandbox environment.

Remediation

Users can upgrade to Firefox 147 or Firefox ESR 115.32 or 140.7 to address this vulnerability.

Added: Jan 13, 2026, 2:34 PM
Updated: Jan 13, 2026, 9:34 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.