Junglewise Threat Intelligence

CVE-2026-92018: Mozilla Firefox sandbox escape in DOM: Core & HTML

CVE-2026-92018 · Severity: critical · CVSS 9.6 · Published 2026-09-15

Executive brief

Firefox and Thunderbird's DOM (Document Object Model) engine contains a sandbox escape vulnerability that could allow an attacker to break out of the browser's security boundaries and gain unauthorized access to system resources or other browser data. This vulnerability affects multiple versions of Firefox and Thunderbird and has been patched in recent releases. An attacker could potentially exploit this to bypass browser security protections and compromise user data or system integrity.

Technical details

CVE-2026-92018 is a sandbox escape vulnerability in the DOM: Core & HTML component of Firefox and Thunderbird. The vulnerability allows an attacker to bypass the browser sandbox through improper boundary conditions or logic errors in the DOM implementation. The attack is likely triggered through malicious web content that the user visits, requiring no additional authentication or local access. Successful exploitation enables an attacker to escape the restricted execution environment and potentially execute arbitrary code with browser privileges or access protected resources. The vulnerability was patched in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox below 156
  • Mozilla Firefox ESR 115.x below 115.41, 140.x below 140.16, 153.x below 153.3
  • Mozilla Thunderbird below 156, 140.x below 140.16, 153.x below 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3

References

Related threats