Junglewise Threat Intelligence

CVE-2026-92050: Mozilla Firefox XPConnect race condition sandbox escape

CVE-2026-92050 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a sandbox escape vulnerability in the XPConnect component caused by a race condition. An attacker who tricks a user into visiting a malicious webpage or opening a crafted email attachment could bypass browser security boundaries and gain the ability to execute arbitrary code with elevated privileges, potentially compromising user data and system security.

Technical details

A race condition exists in Mozilla Firefox's XPConnect component that allows circumvention of the browser sandbox. XPConnect is Firefox's bridge between JavaScript and C++ code, and the vulnerability stems from improper synchronization between concurrent operations. The attack vector is network-based, requiring user interaction (visiting a malicious website or opening a crafted email in Thunderbird). An attacker can exploit this race condition to break out of the sandbox, potentially achieving arbitrary code execution at the privilege level of the browser process or higher. The vulnerability was fixed in Firefox 156 and Thunderbird 156, released on 2026-09-15.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Thunderbird before 156

Timeline

  • 2026-09-15: disclosed: CVE-2026-92050 disclosed by Mozilla Security Advisory MFSA2026-90
  • 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156

References

Related threats