Improper access control in Mozilla products - CVE-2026-12313
Published: June 16, 2026
Firefox for Android
Mozilla Firefox
Firefox ESR
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and escape the sandbox.
The vulnerability exists due to improper access control in the Security: Process Sandboxing component when enforcing sandbox restrictions. A remote attacker can trigger the vulnerable behavior to disclose sensitive information and escape the sandbox.