Executive brief
Firefox and Thunderbird contain a race condition vulnerability in the DOM: Content Processes component that could allow an attacker to exploit timing-dependent behavior. An attacker could potentially cause a denial of service, memory corruption, or execute arbitrary code. The vulnerability has been patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Technical details
A race condition exists in the DOM: Content Processes component of Firefox and Thunderbird, identified as CVE-2026-92042. The vulnerability arises from improper synchronization or timing-dependent behavior when handling inter-process communication between content and parent processes. An attacker could trigger the race condition through malicious web content or by crafting specific network-based attacks to exploit the timing window. Successful exploitation could result in memory corruption, denial of service, or potential code execution. Patches are available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92042 disclosed in Mozilla Security Advisory MFSA2026-90
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3