Junglewise Threat Intelligence

CVE-2026-92038: Mozilla Firefox mitigation bypass in Remote Settings Client

CVE-2026-92038 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

A security mitigation designed to protect Firefox users from certain attacks can be bypassed through the Remote Settings Client component. This allows an attacker to circumvent browser security controls that normally prevent malicious code execution. The vulnerability affects multiple Mozilla products including Firefox, Firefox ESR, Thunderbird, and impacts user safety when browsing untrusted websites.

Technical details

The vulnerability is a mitigation bypass in the Remote Settings Client component, allowing attackers to circumvent security protections. The Remote Settings Client is used to manage browser policies and settings via remote configuration. An attacker with network access can exploit this to bypass mitigations that normally protect against code execution and privilege escalation. The vulnerability is network-reachable and does not require user authentication or interaction. Patches were released in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: Vulnerability announced by Mozilla
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats