Executive brief
Firefox and Thunderbird contain an information disclosure vulnerability in their Graphics: ImageLib component, which handles image rendering in web content. An attacker could exploit this flaw to leak sensitive data from the browser's memory, potentially exposing user credentials, cached content, or other confidential information stored during browsing sessions.
Technical details
This vulnerability is an information disclosure flaw in the Graphics: ImageLib component of Firefox and Thunderbird, which is responsible for processing and rendering image data in web content. The root cause involves improper handling of image data in memory, potentially allowing an attacker to read sensitive information from the browser process. The attack vector is network-based; exploitation requires user interaction (visiting a malicious website or opening a crafted document). An attacker can extract confidential data from browser memory, though the flaw does not enable code execution or privilege escalation. The vulnerability is patched in Firefox 156, Firefox ESR 140.16 and 153.3, Thunderbird 156, and Thunderbird ESR 140.16 and 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 140.16 and 153.x before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird ESR before 140.16 and 153.x before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92031 published
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird ESR 140.16, and Thunderbird ESR 153.3