CVE-2025-13026: Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component
Published Nov 11, 2025
·Updated
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<145
Mozilla Firefox<145
145
Mozilla Thunderbird<145
145
Mozilla Firefox<145.0
Event History
Nov 11, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 13, 2025
Updated
via Mozilla·12:00 AM
Affected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-13026?
CVE-2025-13026 is categorized as a critical vulnerability that allows sandbox escape due to incorrect boundary conditions.
2
How do I fix CVE-2025-13026?
To mitigate CVE-2025-13026, update your Firefox browser to version 145 or later.
3
What versions of Firefox are affected by CVE-2025-13026?
CVE-2025-13026 affects all versions of Firefox prior to 145.
4
What components are involved in CVE-2025-13026?
CVE-2025-13026 involves the Graphics: WebGPU component of Firefox.
5
Can CVE-2025-13026 lead to data compromise?
Yes, CVE-2025-13026 can lead to data compromise by allowing unauthorized access through a sandbox escape.