Junglewise Threat Intelligence

CVE-2026-92034: Mozilla Firefox site isolation issue in Graphics component

CVE-2026-92034 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a site isolation vulnerability in their graphics rendering engine that could allow malicious websites to break through the browser's security boundaries and access content from other websites. An attacker could exploit this to steal sensitive data from other open websites, including login credentials and personal information. This flaw was patched in Firefox 156 and Thunderbird 156.

Technical details

CVE-2026-92034 is a site isolation issue in the Graphics component of Firefox and Thunderbird. Site isolation vulnerabilities occur when security boundaries between different websites are improperly enforced, allowing one site's JavaScript or resources to access data from another site. The vulnerability exists in the graphics rendering subsystem and affects versions prior to Firefox 156 and Thunderbird 156. An attacker can exploit this via a malicious website without requiring user authentication beyond visiting the site. The fix is available in Firefox 156 and Thunderbird 156.

Affected products

  • Mozilla Firefox prior to 156
  • Mozilla Thunderbird prior to 156

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156

References

Related threats