Sandbox Escape Vulnerability in Firefox Graphics Component
CVE-2026-92032

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92032?

A sandbox escape vulnerability affecting the graphics component of Firefox allows an attacker to exploit an invalid pointer. Successfully leveraging this vulnerability can compromise the isolation mechanisms intended to restrict web content's access to the underlying system. This could potentially lead to unauthorized access to sensitive system resources. The issue has been mitigated in the latest versions of Firefox and Firefox ESR. It's crucial for users to update their browsers to ensure protection against potential exploits.

Affected Version(s)

Firefox 140.16

Firefox 153.3

Firefox 156

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.