Junglewise Threat Intelligence

CVE-2026-92071: Mozilla Firefox sandbox escape in Widget: Win32 component

CVE-2026-92071 · Severity: critical · CVSS 9.6 · Published 2026-09-15

Executive brief

Firefox's Win32 widget component contains a flaw that allows attackers to escape the browser's security sandbox through incorrect boundary condition checks. A successful exploit could allow malicious web content to break out of the sandbox and access the underlying operating system with the privileges of the user running Firefox, potentially leading to full system compromise.

Technical details

This vulnerability is a sandbox escape caused by incorrect boundary condition validation in the Widget: Win32 component. The flaw allows an attacker to bypass browser sandbox restrictions through crafted input that exploits the boundary condition check. Attack requires network connectivity and user interaction (opening a malicious web page or email), but no authentication is needed. A successful exploit enables arbitrary code execution outside the sandbox with the privileges of the user's browser process. The vulnerability is fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-92071 published
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3

References

Related threats