Executive brief
Firefox's Reader Mode component contains a site isolation vulnerability that could allow malicious websites to bypass security boundaries designed to isolate web content. This weakness could enable attackers to access data or functionality from other websites visited in the same browser session, compromising user privacy and security.
Technical details
A site isolation vulnerability exists in the Reader Mode component of Firefox and Thunderbird. Site isolation is a security mechanism that enforces boundaries between different website origins to prevent cross-site data theft. The vulnerability allows bypassing these isolation protections, potentially enabling attackers on a malicious website to access sensitive data from other websites or browser contexts. The issue was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. No evidence of active exploitation in the wild has been reported.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed: Published as CVE-2026-92068
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3