Sandbox Escape Vulnerability in Firefox Win32 Components
CVE-2026-92065

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92065?

This vulnerability allows an attacker to escape the sandbox due to inadequate management of boundary conditions in the Widget: Win32 component. By exploiting this issue, malicious actors may gain unauthorized access or control over restricted functionalities. Mozilla addressed and validated the resolution in Firefox version 156 and Firefox ESR 153.3, highlighting the importance of keeping systems up to date to mitigate security risks.

Affected Version(s)

Firefox 153.3

Firefox 156

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.