Junglewise Threat Intelligence

CVE-2026-92074: Mozilla Firefox and Thunderbird Popup Blocker mitigation bypass

CVE-2026-92074 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird web browsers include a Popup Blocker feature to prevent malicious pop-up windows from appearing without user consent. A vulnerability in this component allows attackers to bypass this protection, potentially displaying unwanted or malicious pop-ups to users. This could enable phishing attacks, malware distribution, or unwanted content exposure.

Technical details

CVE-2026-92074 is a mitigation bypass vulnerability in the Popup Blocker component of Firefox and Thunderbird. The vulnerability allows an attacker to bypass the browser's pop-up blocking mechanism through techniques not disclosed in the available advisory fragments. An attacker can exploit this via a malicious website or content delivered over the network to bypass pop-up restrictions. Successful exploitation enables the display of arbitrary pop-up windows that would normally be blocked, potentially for phishing, malware delivery, or other malicious purposes. The vulnerability was patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: Published in Mozilla Foundation Security Advisory 2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats