Executive brief
Firefox's Win32 widget component contains a flaw that allows attackers to escape the browser's security sandbox through incorrect boundary condition checks. A successful exploit could allow malicious web content to break out of the sandbox and access the underlying operating system with the privileges of the user running Firefox, potentially leading to full system compromise.
Technical details
This vulnerability is a sandbox escape caused by incorrect boundary condition validation in the Widget: Win32 component. The flaw allows an attacker to bypass browser sandbox restrictions through crafted input that exploits the boundary condition check. Attack requires network connectivity and user interaction (opening a malicious web page or email), but no authentication is needed. A successful exploit enables arbitrary code execution outside the sandbox with the privileges of the user's browser process. The vulnerability is fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92071 published
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3