CVE-2026-8945
7.5Mozilla · Firefox
A sandbox escape vulnerability in Mozilla Firefox and Firefox Focus for Android allows an attacker to bypass security restrictions.
Executive summary
A critical sandbox escape vulnerability in Mozilla Firefox for Android could allow an attacker to bypass security boundaries and gain unauthorized system access.
Vulnerability
This is a sandbox escape vulnerability that can be exploited by an unauthenticated attacker requiring high complexity and user interaction to successfully compromise the application's security container.
Business impact
While the CVSS score is 7.5, the potential for a sandbox escape represents a critical threat to mobile device security. A successful exploit could allow an attacker to break out of the browser's security boundaries, leading to unauthorized access to device data or additional system-level compromises.
Remediation
Immediate Action: Update the Mozilla Firefox application on all Android devices to version 151 or later immediately.
Proactive Monitoring: Monitor mobile device management (MDM) platforms for devices running outdated versions of the browser.
Compensating Controls: Restrict the installation of untrusted or non-essential mobile applications that might interact with browser data.
Exploitation status
Public Exploit Available: unknown
Analyst recommendation
Mobile device security is paramount; administrators must enforce the update to Firefox version 151 across the mobile fleet. Failure to patch may expose mobile endpoints to full system compromise if an attacker successfully escapes the browser sandbox.