Sandbox Escape Vulnerability in Mozilla Firefox and Firefox ESR
CVE-2026-92048

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92048?

A vulnerability has been identified in the Mozilla Firefox and Firefox ESR that allows for sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This flaw could potentially be exploited to breach the security of the environment the application operates in. Mozilla has addressed this issue in Firefox version 156 and Firefox ESR version 153.3, ensuring users are protected against this vulnerability.

Affected Version(s)

Firefox 153.3

Firefox 156

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.