Junglewise Threat Intelligence

CVE-2026-92039: Mozilla Firefox mitigation bypass in DOM Notifications component

CVE-2026-92039 · Severity: medium · CVSS 6.3 · Published 2026-09-15

Executive brief

Firefox includes a notifications feature in its DOM (page structure) layer that can display alerts and messages to users. A mitigation bypass vulnerability in this component could allow an attacker to circumvent security protections designed to prevent malicious use of notifications, potentially leading to social engineering attacks, phishing, or other user-facing exploits.

Technical details

A mitigation bypass vulnerability exists in the DOM Notifications component of Firefox, allowing attackers to circumvent security mitigations designed to protect against abuse of the notification API. The vulnerability affects the browser's protection mechanisms rather than introducing a direct memory safety flaw. The attack is network-based and does not require authentication or special privileges. An attacker can bypass notification security policies, potentially enabling delivery of spoofed or malicious notifications to users. The vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: Published in Mozilla Security Advisory MFSA2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats