Executive brief
Firefox and Thunderbird include a crash reporting component that processes application crashes. A privilege escalation vulnerability in this component allows an attacker to execute code with elevated privileges, potentially compromising the security of the user's system and any data handled by the browser or email client.
Technical details
CVE-2026-92047 is a privilege escalation vulnerability in the Crash Reporting component of Firefox and Thunderbird. The vulnerability allows an attacker to gain elevated privileges through the crash reporting mechanism. While specific attack preconditions and root cause details are not fully disclosed in the available advisory content, the CVSS score of 8.8 indicates a high-impact vulnerability requiring network or local access. The vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird ESR before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92047 published on NVD
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3