Sandbox Escape Vulnerability in Mozilla Firefox and Firefox ESR
CVE-2026-92064

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92064?

This vulnerability allows for a sandbox escape in the Widget: Win32 component due to incorrect boundary conditions. Attackers could potentially exploit this flaw to execute unintended commands outside the restricted environment. The issue has been addressed in Firefox version 156 and Firefox ESR version 153.3, ensuring enhanced security for users against exploitation attempts.

Affected Version(s)

Firefox 153.3

Firefox 156

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.