PT-2026-40046 · Mozilla+1 · Firefox+1
Andrew Mccreight
+1
·
Published
2026-05-12
·
Updated
2026-06-02
·
CVE-2026-8401
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 150.0.3
Firefox ESR versions prior to 115.36
Firefox ESR versions prior to 140.11
Description
A sandbox escape exists in the Profile Backup component. A sandbox is a security mechanism for separating running programs, ensuring that code in a sandbox cannot access resources outside of it.
Recommendations
Update to version 150.0.3.
Update to ESR version 115.36.
Update to ESR version 140.11.
Fix
DoS
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Rocky Linux