CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.12 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 152 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.12 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 152 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 140.12
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-12289
- CVE-2026-12290
- CVE-2026-12291
- CVE-2026-12292
- CVE-2026-12294
- CVE-2026-12295
- CVE-2026-12298
- CVE-2026-12296
- CVE-2026-12297
- CVE-2026-12299
- CVE-2026-12329
- CVE-2026-12302
- CVE-2026-12304
- CVE-2026-12305
- CVE-2026-12306
- CVE-2026-12307
- CVE-2026-12308
- CVE-2026-12309
- CVE-2026-12310
- CVE-2026-12311
- CVE-2026-12312
- CVE-2026-12313
- CVE-2026-12314
- CVE-2026-12315
- CVE-2026-12330
- CVE-2026-12324
- CVE-2026-12325
- CVE-2026-12327
- CVE-2026-12328
- CVE-2026-12293
- CVE-2026-12300
- CVE-2026-12301
- CVE-2026-12303
- CVE-2026-12316
- CVE-2026-12317
- CVE-2026-12318
- CVE-2026-12319
- CVE-2026-12320
- CVE-2026-12321
- CVE-2026-12322
- CVE-2026-12323
- CVE-2026-12326
Frequently Asked Questions
What is the severity of CVE-2026-12313?
The severity of CVE-2026-12313 is medium with a score of 4.7 according to the CVSS 3.1 system.
How do I fix CVE-2026-12313?
To fix CVE-2026-12313, update to Firefox 152, Firefox ESR 140.12, Thunderbird 152, or Thunderbird 140.12.
What type of vulnerability is CVE-2026-12313?
CVE-2026-12313 is classified as an information disclosure and sandbox escape vulnerability.
What component is affected by CVE-2026-12313?
CVE-2026-12313 affects the Security: Process Sandboxing component.
When was CVE-2026-12313 published?
CVE-2026-12313 was published on June 16, 2026.