Executive brief
Firefox and Thunderbird's document editing component contains a boundary condition vulnerability that could allow attackers to execute arbitrary code or escape the browser sandbox. This affects millions of users who rely on these browsers and email client for daily communication and web browsing. An attacker could exploit this to compromise system security, steal sensitive data, or install malware.
Technical details
The vulnerability is an incorrect boundary condition flaw in the DOM Editor component that affects Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The boundary condition error could allow an attacker to write out-of-bounds memory, potentially leading to code execution or sandbox escape. The flaw is remotely exploitable over the network without requiring user authentication; however, user interaction (such as visiting a malicious webpage or opening a specially crafted email) may be required depending on the attack scenario. Mozilla has patched this vulnerability in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. The CVSS score of 9.3 reflects the critical nature of the impact (confidentiality, integrity, and availability all compromised).
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92059 published
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3