Firefox sandbox escape via DOM boundary conditions <148
CVE-2026-2778 Published on February 24, 2026

Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, and Firefox ESR < 140.8.

NVD


Products Associated with CVE-2026-2778

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-2778 are published in these products:

 
 

Affected Versions

Mozilla Firefox: Mozilla Firefox ESR: Mozilla Firefox ESR: Mozilla Thunderbird: Mozilla Thunderbird: