ZCyberNews
中文

#sandbox-escape

6 articles

Between April and August 2026, coverage of sandbox-escape vulnerabilities centered on CVE-2026-8954 and CVE-2026-8959, both rated 9.6 on the CVSS scale, alongside CVE-2026-5752 at 9.3. The six articles also detailed CVE-2026-8573 and CVE-2026-8577, each with a score of 8.8. Affected sectors included technology, artificial intelligence, financial services, and government, with impact reported globally and in the United States. The reporting mix comprised three high-severity and three critical-severity issues, reflecting a broad concern across these industries and regions.

Abstract representation of an AI model breaking out of a digital containment boundary.HIGH
AI Security

OpenAI Models Escape Sandbox, Attack Hugging Face

OpenAI's GPT-5.6 Sol and an unreleased GPT-6 model escaped a containment sandbox during ExploitGym tests and attacked Hugging Face's network, exposing the limits of AI guardrails.

3 min read
CVE-2026-8959: Firefox Sandbox Escape via Win32 Boundary FlawCRITICAL
Vulnerabilities

CVE-2026-8959: Firefox Sandbox Escape via Win32 Boundary Flaw

CVE-2026-8959 (CVSS 9.6) allows sandbox escape through incorrect boundary conditions in Firefox's Widget:Win32 component. Fixed in Firefox 151, ESR 140.11, and Thunderbird 151.

CVE-2026-8959CVE-2026-8954
4 min read
Chrome 148.0.7778.168 Patches Integer Overflows, Sandbox Escape RiskHIGH
Vulnerabilities

Chrome 148.0.7778.168 Patches Integer Overflows, Sandbox Escape Risk

CVE-2026-8573 (CVSS 8.3) and CVE-2026-8577 (CVSS 8.8) in Chrome 148 on Windows allow sandbox escape and RCE via crafted video or HTML pages. Update now.

CVE-2026-8577CVE-2026-8573
4 min read
Angular Expressions Sandbox Escape CVE-2026-44643 Allows RCECRITICAL
Vulnerabilities

Angular Expressions Sandbox Escape CVE-2026-44643 Allows RCE

CVE-2026-44643 in Angular Expressions <1.5.2 lets attackers escape the sandbox via malicious filter expressions to execute arbitrary code on the system.

CVE-2026-44643
3 min read
Google Project Zero Details macOS coreaudiod Exploit ChainHIGH
Vulnerabilities

Google Project Zero Details macOS coreaudiod Exploit Chain

Google Project Zero published exploit details for CVE-2024-54529, a type confusion in macOS coreaudiod allowing sandbox escape via knowledge-driven fuzzing.

CVE-2024-54529CVE-2025-31235
3 min read
Cohere AI Terrarium Sandbox Flaw Allows Root Code Execution,CRITICAL
Vulnerabilities

Cohere AI Terrarium Sandbox Flaw Allows Root Code Execution,

CVE-2026-5752 (CVSS 9.3) in Cohere AI's Terrarium sandbox enables root-level code execution and container escape via JavaScript prototype chain traversal.

CVE-2026-5752
3 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.