Junglewise Threat Intelligence

CVE-2026-92066: Mozilla Firefox sandbox escape in Profile Backup

CVE-2026-92066 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Firefox's Profile Backup feature contains a sandbox escape vulnerability that allows an attacker to break out of the browser's security sandbox and execute code with elevated privileges. This could lead to unauthorized access to user data, installation of malware, or full system compromise. The vulnerability affects Firefox versions prior to 156 and has been patched.

Technical details

This is a sandbox escape vulnerability in the Profile Backup component of Firefox. The attack is reachable over the network and does not require authentication or user interaction beyond normal browser usage. A successful exploit breaks the browser sandbox, allowing an attacker to execute arbitrary code outside the restricted execution environment. This could enable theft of sensitive data stored in user profiles or system-level attacks. The vulnerability has been fixed in Firefox 156 and Thunderbird 156.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Thunderbird before 156

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156

References

Related threats