Junglewise Threat Intelligence

CVE-2026-92035: Mozilla Firefox sandbox escape in Graphics component

CVE-2026-92035 · Severity: critical · CVSS 9.6 · Published 2026-09-15

Executive brief

Firefox's graphics processing engine contains a boundary condition flaw that allows attackers to escape the browser's security sandbox. An attacker can exploit this vulnerability through a malicious webpage to break out of the browser's isolated execution environment and potentially gain unauthorized access to the underlying system or user data.

Technical details

This is a sandbox escape vulnerability caused by incorrect boundary condition checks in Firefox's Graphics component. The flaw allows an attacker to break out of the browser's security sandbox through crafted graphics operations. The attack is triggered via network delivery of a malicious webpage (user interaction required to load the page). Exploitation enables arbitrary code execution with the privileges of the browser process, potentially leading to full system compromise. The vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-92035 published
  • 2026-09-15: patched: Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3 released with fix

References

Related threats