Executive brief
Firefox and Thunderbird include a networking component that handles internet communication for the browser and email client. An information disclosure vulnerability in this component could allow attackers to leak sensitive data transmitted or cached during network operations, potentially exposing user communications, credentials, or browsing activity.
Technical details
CVE-2026-92070 is an information disclosure vulnerability in the Networking component of Mozilla Firefox and Thunderbird. The vulnerability allows unauthorized access to sensitive information handled by the networking subsystem. The exact attack vector and preconditions are not detailed in the available advisory text, but the moderate CVSS score of 4.3 suggests limited exploitability or impact scope. Mozilla patched this issue in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. No evidence of active exploitation in the wild has been reported.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3