Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-8945 is a sandbox escape vulnerability affecting Firefox and Firefox Focus on Android devices, rated as high severity (CVSS 7.5). Sandbox escapes are particularly dangerous because they allow attackers to break out of the restricted execution environment designed to contain untrusted code, potentially gaining access to system resources, user data, and other sensitive information. This vulnerability affects Android users who rely on Firefox as their primary browser, putting millions of devices at risk until they update to version 151 or later. The vulnerability is mapped to CWE-693 (Protection Mechanism Failure), indicating a fundamental breakdown in the security boundary that isolates browser processes from the underlying operating system.
While this CVE currently shows zero matching Casky skills due to its very recent discovery and lack of mapped MITRE ATT&CK techniques, the underlying attack patterns would typically involve Defense Evasion and Privilege Escalation techniques. Security practitioners using Casky's extended reasoning capabilities should look for behavioral indicators including: unusual process creation or inter-process communication attempts from browser contexts, attempts to access filesystem paths outside the expected sandbox boundaries, and privilege escalation activities following browser exploitation. Organizations should prioritize patching Firefox and Firefox Focus to version 151 immediately, monitor for exploitation attempts in network logs, and leverage Casky's expanding skill library to correlate sandbox escape indicators with other MITRE ATT&CK techniques as threat intelligence on this vulnerability matures.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-8945. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation