Executive brief
Firefox and Thunderbird process web content using an Animation component that contains a boundary condition vulnerability. An attacker could exploit this flaw to achieve privilege escalation or potentially execute arbitrary code with elevated permissions.
Technical details
This vulnerability involves incorrect boundary conditions in the DOM: Animation component, allowing a boundary condition to be exploited. The vulnerability can be triggered through network vectors without requiring authentication. An attacker can achieve privilege escalation through boundary condition bypass. The issue has been patched in Firefox 156 and Thunderbird 156.
Affected products
- Mozilla Firefox before 156
- Mozilla Thunderbird before 156
Timeline
- 2026-09-15: disclosed: CVE-2026-92037 published
- 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156