Executive brief
Firefox and Thunderbird contain a vulnerability in their SVG (Scalable Vector Graphics) rendering component that can be exploited to cause a denial-of-service condition. When a user encounters a specially crafted SVG file or web page, an attacker can crash the application, disrupting productivity and user access to services relying on these applications. This has been patched in recent versions.
Technical details
CVE-2026-92077 is a denial-of-service vulnerability in the SVG component of Mozilla Firefox and Thunderbird. The vulnerability allows remote attackers to crash the affected application by triggering unspecified behavior in SVG rendering logic. The attack vector is network-based and requires user interaction (viewing a malicious SVG or web page). The vulnerability has been patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3, and there is no public evidence of active exploitation in the wild.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed: Published on NVD and Mozilla security advisory
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3