Input validation error in Firefox ESR - CVE-2026-7321
Published: April 28, 2026
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the WebRTC: Networking component when handling WebRTC network traffic. A remote attacker can trigger specially crafted WebRTC network interactions to escape the sandbox.
User interaction is required to visit a specially crafted website or URL.