Executive brief
Firefox and Thunderbird web browsers contain a mitigation bypass vulnerability in their DOM networking component. An attacker could exploit this to circumvent security protections designed to prevent unauthorized network access, potentially leading to data exposure or unauthorized communication.
Technical details
This vulnerability is a mitigation bypass in the DOM: Networking component affecting Mozilla Firefox and Thunderbird. The issue allows attackers to circumvent existing security mitigations designed to protect DOM-level networking operations, potentially enabling network-based attacks. The vulnerability was reported by Atsushi Sada and is tracked in Mozilla bug 2029482. Patches are available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. Network-level attack vector is likely given the networking component context, though specific preconditions for exploitation are not publicly disclosed due to the security advisory format.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3