CVE-2026-12295 is a sandbox escape vulnerability in the DOM Navigation component of Mozilla Firefox and Thunderbird. Exploitation permits escape from intended browser sandbox restrictions through the affected component.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real proof-of-concept exploit for CVE-2026-12295, a Firefox UXSS/origin-confusion issue in which a compromised content process forges a PNecko::PDocumentChannel constructor carrying nsDocShellLoadState with SrcdocData set alongside a non-about:srcdoc URI. On vulnerable Firefox builds, the parent process accepts the forged load state and docshell serves attacker-controlled srcdoc HTML as the document at the forged URI's origin, yielding same-origin access to victim resources. Repository structure: the core exploit logic is split across srcdoc.html and forge.py. forge.py constructs a byte-accurate forged IPC message based on a captured real DocumentChannel message template, serializing a target URI of http://localhost:8778/nav.html and embedding attacker HTML that fetches /secret.txt and exfiltrates it to http://127.0.0.1:8778/exfil. It outputs forge.bin and forge.json for runtime use. srcdoc.html is the browser-side exploit page; it loads wasm-bytes.js, uses WebAssembly-based arbitrary read/write and call primitives (stage-1 exploit support) to locate Firefox/XUL structures in memory, opens an about:blank popup to obtain a same-process top-level BrowsingContext, patches runtime fields into the forged message, constructs a real IPC::Message object, writes the forged payload into it, and sends it through MessageChannel::Send on the live content-parent channel. Supporting files: wasm-bytes.js contains raw WebAssembly byte arrays implementing the memory corruption primitives used by srcdoc.html. parse_dc.py is a helper/parser for captured PDocumentChannel constructor messages and is used by forge.py for validation and reverse engineering. mdrive2.py is a Marionette automation harness that launches a local Firefox Nightly build, waits, and navigates to the exploit page. irun is a zsh orchestration script that prepares the profile, launches the harness, attaches LLDB to the Firefox parent process, and collects evidence from logs. profile.user.js sets permissive Firefox prefs needed for the demo. nav.html and secret.txt are demo fixtures representing the victim-origin page and sensitive data. Capabilities: the exploit does not achieve initial code execution by itself; it assumes an already compromised Firefox content process. Given that prerequisite, it weaponizes the browser IPC path to perform a cross-origin document load confusion, resulting in UXSS, same-origin reads, and exfiltration. The included payload is operational and demonstrates theft of a same-origin secret plus visible page takeover ('PWNED at <origin>').
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sandbox-escape vulnerability in Thunderbird's DOM Navigation component.
A sandbox escape vulnerability in Firefox affecting navigation or process sandboxing mechanisms.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.