Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Firefox | Mozilla | * | 152.0 (excluding) |
| Firefox | Mozilla | 140.0 (including) | 140.12.0 (excluding) |
| Thunderbird | Mozilla | * | 152.0.0 (excluding) |
| Thunderbird | Mozilla | 140.0 (including) | 140.12.0 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | firefox-0:140.12.0-1.el10_2 | * |
| Red Hat Enterprise Linux 8 | RedHat | firefox-0:140.12.0-1.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | firefox-0:140.12.0-1.el9_8 | * |
| Mozjs102 | Ubuntu | esm-apps/noble | * |
| Mozjs102 | Ubuntu | jammy | * |
| Mozjs102 | Ubuntu | noble | * |
| Mozjs115 | Ubuntu | noble | * |
| Mozjs52 | Ubuntu | esm-apps/focal | * |
| Mozjs52 | Ubuntu | esm-infra/bionic | * |
| Mozjs68 | Ubuntu | esm-infra/focal | * |
| Mozjs78 | Ubuntu | esm-apps/jammy | * |
| Mozjs78 | Ubuntu | jammy | * |
| Mozjs91 | Ubuntu | jammy | * |
| Thunderbird | Ubuntu | jammy | * |