CRITICALCVE-2026-8401Published Modified CNA mozilla
CVE-2026-8401: Sandbox escape in the Profile Backup component
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
Metrics
- CVSS v3.1
- 9.8
- Severity
- CRITICAL
- Fixed in
- 115.36
- Affected Products
- 2
Fix available
115.36140.11150.0.3
Affected packages
- Mozilla / FirefoxFixed in 115.36, 140.11, 150.0.3
- Mozilla / ThunderbirdFixed in 140.11
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H