Junglewise Threat Intelligence

CVE-2026-92079: Mozilla Firefox mitigation bypass in Widget: Win32

CVE-2026-92079 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Firefox is a widely-used web browser that millions rely on daily for secure web browsing. A mitigation bypass vulnerability in its Windows-specific component could allow an attacker to circumvent security protections built into the browser, potentially leading to unauthorized code execution or data compromise. Mozilla has patched this vulnerability in Firefox 156 and Firefox ESR 153.3.

Technical details

This vulnerability is a mitigation bypass in Firefox's Widget: Win32 component, which handles Windows-specific UI and platform integration. A mitigation bypass allows an attacker to defeat security mechanisms (such as address space layout randomization, code signing verification, or sandboxing), potentially enabling arbitrary code execution or privilege escalation. The attack vector and specific preconditions are not disclosed in the available references, but the critical severity rating suggests network reachability and low user interaction friction. Mozilla released patches in Firefox 156 (release version) and Firefox ESR 153.3 (Extended Support Release).

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird ESR before 153.3

Timeline

  • 2026-09-15: disclosed: Published as CVE-2026-92079
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3

References

Related threats