CVE-2026-8945

7.5

Mozilla · Firefox

A sandbox escape vulnerability in Mozilla Firefox and Firefox Focus for Android allows an attacker to bypass security restrictions.

Executive summary

A critical sandbox escape vulnerability in Mozilla Firefox for Android could allow an attacker to bypass security boundaries and gain unauthorized system access.

Vulnerability

This is a sandbox escape vulnerability that can be exploited by an unauthenticated attacker requiring high complexity and user interaction to successfully compromise the application's security container.

Business impact

While the CVSS score is 7.5, the potential for a sandbox escape represents a critical threat to mobile device security. A successful exploit could allow an attacker to break out of the browser's security boundaries, leading to unauthorized access to device data or additional system-level compromises.

Remediation

Immediate Action: Update the Mozilla Firefox application on all Android devices to version 151 or later immediately.

Proactive Monitoring: Monitor mobile device management (MDM) platforms for devices running outdated versions of the browser.

Compensating Controls: Restrict the installation of untrusted or non-essential mobile applications that might interact with browser data.

Exploitation status

Public Exploit Available: unknown

Analyst recommendation

Mobile device security is paramount; administrators must enforce the update to Firefox version 151 across the mobile fleet. Failure to patch may expose mobile endpoints to full system compromise if an attacker successfully escapes the browser sandbox.

More Mozilla CVEs