Executive brief
Firefox and Thunderbird contain a spoofing vulnerability in their graphics processing component caused by an invalid pointer dereference. An attacker could exploit this flaw to display misleading content or fake interface elements, potentially deceiving users into disclosing sensitive information or performing unintended actions. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Technical details
CVE-2026-92051 is a spoofing vulnerability triggered by an invalid pointer in the Graphics component of Firefox and Thunderbird. The root cause stems from improper pointer validation within graphics rendering code, allowing an attacker to trigger memory access violations that manifest as spoofing behavior. The vulnerability is remotely exploitable over the network without requiring user authentication or special preconditions beyond visiting a malicious webpage. An attacker can leverage this to display spoofed content that impersonates legitimate interfaces or third-party sites, potentially facilitating phishing or social engineering attacks. Mozilla released patches in Firefox 156 and Thunderbird 156 to address this issue.
Affected products
- Mozilla Firefox before 156
- Mozilla Thunderbird before 156
Timeline
- 2026-09-15: disclosed: CVE-2026-92051 publicly disclosed
- 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156