Impact
A flaw in Mozilla’s Security: Process Sandboxing component permits an attacker to escape the confined environment and acquire higher privileges than intended, effectively breaking the browser’s isolation model and allowing attackers to execute arbitrary code. The weakness corresponds to a classic elevation of privilege flaw and is formally classified as CWE‑272.
Affected Systems
The vulnerability affects all Firefox builds released before Firefox ESR 153.4 and before Firefox 157. Users running earlier ESR releases, such as ESR 151.x or older, as well as legacy stable releases before version 157, remain exposed and must update to at least the specified patch versions.
Risk and Exploitability
EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, yet the high impact of breaking sandbox containment suggests a serious risk profile. Based on the description, the likely attack vector is from malicious web content interacting with the browser’s process sandbox, allowing a remote or local attacker who can influence web page execution to trigger the escape. The exact probability of exploitation is unknown, but any successful exploitation would grant the attacker code execution privileges within the user’s process space.
OpenCVE Enrichment