Junglewise Threat Intelligence

CVE-2026-92037: Mozilla Firefox incorrect boundary conditions in DOM Animation component

CVE-2026-92037 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird process web content using an Animation component that contains a boundary condition vulnerability. An attacker could exploit this flaw to achieve privilege escalation or potentially execute arbitrary code with elevated permissions.

Technical details

This vulnerability involves incorrect boundary conditions in the DOM: Animation component, allowing a boundary condition to be exploited. The vulnerability can be triggered through network vectors without requiring authentication. An attacker can achieve privilege escalation through boundary condition bypass. The issue has been patched in Firefox 156 and Thunderbird 156.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Thunderbird before 156

Timeline

  • 2026-09-15: disclosed: CVE-2026-92037 published
  • 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156

References

Related threats