Junglewise Threat Intelligence

CVE-2026-92041: Mozilla Firefox mitigation bypass in DOM: Networking component

CVE-2026-92041 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Firefox and Thunderbird web browsers contain a mitigation bypass vulnerability in their DOM networking component. An attacker could exploit this to circumvent security protections designed to prevent unauthorized network access, potentially leading to data exposure or unauthorized communication.

Technical details

This vulnerability is a mitigation bypass in the DOM: Networking component affecting Mozilla Firefox and Thunderbird. The issue allows attackers to circumvent existing security mitigations designed to protect DOM-level networking operations, potentially enabling network-based attacks. The vulnerability was reported by Atsushi Sada and is tracked in Mozilla bug 2029482. Patches are available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. Network-level attack vector is likely given the networking component context, though specific preconditions for exploitation are not publicly disclosed due to the security advisory format.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats