Back

HIGH

Information disclosure, sandbox escape in the Security: Process Sandboxing component

Published May 19, 2026

Description

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published May 19, 2026
Updated May 19, 2026
Reserved May 19, 2026
CISA Vulnrichment
Updated May 19, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 19, 2026
ENISA EUVD
Assigner mozilla
Published May 19, 2026
Updated May 19, 2026
Exploited since n/a
EUVD-2026-30907