LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-12297

mozilla · firefox

Published
CVSS9.6
Severitycritical
WeaknessCWE-119
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Description

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-12297

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-12297.