VYPR
High severity7.5NVD Advisory· Published May 19, 2026· Updated May 19, 2026

CVE-2026-8945

CVE-2026-8945

Description

Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A sandbox escape vulnerability in Firefox and Firefox Focus for Android, fixed in Firefox 151, allows attackers to break out of the browser's security sandbox.

Vulnerability

A sandbox escape vulnerability exists in Firefox and Firefox Focus for Android. The issue is in the browser's sandbox implementation, allowing an attacker to break out of the restricted environment. The vulnerability affects both Firefox and Firefox Focus for Android prior to version 151. It was fixed in Firefox 151, released on May 19, 2026 [1].

Exploitation

An attacker would need to be able to execute code or trigger a script within the browser's sandbox. The exact exploitation details are not publicly disclosed, but the vulnerability was reported by Daisuke Hatakeyama and assigned Bug 2003171 [1][2]. It is likely exploitable via a crafted web page or by combining with other bugs to escape the sandbox.

Impact

Successful exploitation allows the attacker to escape the browser sandbox, gaining the ability to execute arbitrary code outside the sandboxed environment. This could lead to full compromise of the host system, as the sandbox is designed to prevent malicious content from accessing the underlying operating system. The impact is rated as high [1].

Mitigation

The vulnerability is fixed in Firefox 151, and users should update to this version or later. There is no workaround mentioned, and users of Firefox Focus for Android should also ensure they are using the latest version. No known exploits in the wild have been reported, and the vulnerability is not on the CISA Known Exploited Vulnerabilities (KEV) list as of the publication date [1].

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.