Junglewise Threat Intelligence

CVE-2026-92069: Mozilla Firefox spoofing issue in DOM Navigation component

CVE-2026-92069 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a spoofing vulnerability in the DOM Navigation component that could allow an attacker to deceive users about the true origin or destination of a webpage or action. This could enable phishing attacks, credential theft, or malware distribution by making malicious content appear to come from legitimate sources. The vulnerability has been patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Technical details

A spoofing vulnerability exists in the DOM Navigation component of Mozilla Firefox and Thunderbird, allowing an attacker to misrepresent navigation origins or destinations to users. The vulnerability is triggered through network-based attack vectors and requires user interaction (e.g., clicking a link or visiting a malicious page). An attacker could exploit this to display false URL bars, protocol indicators, or origin information, enabling phishing or social engineering attacks. The issue has been addressed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats