SB2026091579 - Multiple vulnerabilities in Mozilla Firefox
Published: September 15, 2026 Updated: September 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 75 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2026-92058)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the Graphics component when processing input. A remote attacker can process input to cause memory corruption.
2) Information disclosure (CVE-ID: CVE-2026-92070)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in the Networking component when processing input. A remote attacker can process input to disclose sensitive information.
3) Input validation error (CVE-ID: CVE-2026-92069)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to conduct spoofing attacks.
The vulnerability exists due to an unspecified flaw in the DOM: Navigation component when processing input. A remote attacker can process input to conduct spoofing attacks.
4) Improper isolation or compartmentalization (CVE-ID: CVE-2026-92068)
CWE-ID: CWE-653 - Improper isolation or compartmentalization
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper isolation in the Reader Mode component when processing input. A remote attacker can process input to bypass site isolation.
5) Use-after-free (CVE-ID: CVE-2026-92067)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the Widget: Gtk component when processing input. A remote attacker can process input to cause memory corruption.
6) Input validation error (CVE-ID: CVE-2026-92065)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the Widget: Win32 component when processing input. A remote attacker can process input to escape the sandbox.
7) Input validation error (CVE-ID: CVE-2026-92064)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the Widget: Win32 component when processing input. A remote attacker can process input to escape the sandbox.
8) Input validation error (CVE-ID: CVE-2026-92062)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an unspecified flaw in the Session Restore component when processing input. A remote attacker can process input to escalate privileges.
9) Use-after-free (CVE-ID: CVE-2026-92060)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the Internationalization component when processing input. A remote attacker can process input to cause memory corruption.
10) Input validation error (CVE-ID: CVE-2026-92059)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause unspecified security impacts.
The vulnerability exists due to incorrect boundary conditions in the DOM: Editor component when processing input. A remote attacker can process input to cause unspecified security impacts.
11) Input validation error (CVE-ID: CVE-2026-92071)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the Widget: Win32 component when processing input. A remote attacker can process input to escape the sandbox.
12) Protection mechanism failure (CVE-ID: CVE-2026-92057)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security mitigations.
The vulnerability exists due to a protection mechanism failure in the Enterprise Policies component when processing input. A remote attacker can process input to bypass security mitigations.
13) Use-after-free (CVE-ID: CVE-2026-92056)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the Graphics: Text component when processing input. A remote attacker can process input to cause memory corruption.
14) Input validation error (CVE-ID: CVE-2026-92055)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an unspecified flaw in the DevTools component when processing input. A remote attacker can process input to escalate privileges.
15) Input validation error (CVE-ID: CVE-2026-92054)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an unspecified flaw in the Memory component when processing input. A remote attacker can process input to escalate privileges.
16) Input validation error (CVE-ID: CVE-2026-92053)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an unspecified flaw in the Graphics: CanvasWebGL component when processing input. A remote attacker can process input to escalate privileges.
17) Use of Uninitialized Variable (CVE-ID: CVE-2026-92052)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use of uninitialized memory in the Graphics: CanvasWebGL component when processing input. A remote attacker can process input to escalate privileges.
18) Use-after-free (CVE-ID: CVE-2026-92049)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the Widget: Win32 component when processing input. A remote attacker can process input to cause memory corruption.
19) Input validation error (CVE-ID: CVE-2026-92048)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the Widget: Win32 component when processing input. A remote attacker can process input to escape the sandbox.
20) Protection mechanism failure (CVE-ID: CVE-2026-92066)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to an unspecified security flaw in the Profile Backup component when handling profile backups. A remote attacker can trigger the flaw to escape the browser sandbox.
21) Off-by-one (CVE-ID: CVE-2026-92037)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause unspecified security consequences.
The vulnerability exists due to incorrect boundary conditions in the DOM: Animation component when processing animations. A remote attacker can trigger the flaw to cause unspecified security consequences.
22) Use-after-free (CVE-ID: CVE-2026-92040)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing WebAssembly content. A remote attacker can trigger the flaw to cause memory corruption.
23) Race condition (CVE-ID: CVE-2026-92050)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to a race condition in the XPConnect component when handling affected functionality. A remote attacker can trigger the race condition to escape the browser sandbox.
24) Off-by-one (CVE-ID: CVE-2026-92061)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause unspecified security consequences.
The vulnerability exists due to incorrect boundary conditions in the Security: Process Sandboxing component when handling affected functionality. A remote attacker can trigger the flaw to cause unspecified security consequences.
25) Resource exhaustion (CVE-ID: CVE-2026-92063)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified availability flaw in the Audio/Video component when processing media. A remote attacker can trigger the flaw to cause a denial of service.
26) Untrusted Pointer Dereference (CVE-ID: CVE-2026-92051)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform spoofing attacks.
The vulnerability exists due to invalid pointer handling in the Graphics component when handling graphics content. A remote attacker can trigger the flaw to perform spoofing attacks.
27) Improper privilege management (CVE-ID: CVE-2026-92033)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an unspecified security flaw in Firefox for Android when handling affected functionality. A remote attacker can trigger the flaw to escalate privileges.
28) Protection mechanism failure (CVE-ID: CVE-2026-92034)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper site isolation in the Graphics component when handling affected functionality. A remote attacker can trigger the flaw to bypass site isolation.
29) Off-by-one (CVE-ID: CVE-2026-92036)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause unspecified security consequences.
The vulnerability exists due to incorrect boundary conditions in the Networking: HTTP component when processing HTTP data. A remote attacker can trigger the flaw to cause unspecified security consequences.
30) Input validation error (CVE-ID: CVE-2026-92047)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an unspecified flaw in the Crash Reporting component when processing input. A remote attacker can process input to escalate privileges.
31) Protection mechanism failure (CVE-ID: CVE-2026-92079)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security mitigations.
The vulnerability exists due to a protection mechanism failure in the Widget: Win32 component when processing input. A remote attacker can process input to bypass security mitigations.
32) Resource exhaustion (CVE-ID: CVE-2026-92078)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in the Security component when processing input. A remote attacker can process input to cause a denial of service.
33) Resource exhaustion (CVE-ID: CVE-2026-92077)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in the SVG component when processing input. A remote attacker can process input to cause a denial of service.
34) Input validation error (CVE-ID: CVE-2026-92076)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause unspecified security impacts.
The vulnerability exists due to incorrect boundary conditions in the Networking component when processing input. A remote attacker can process input to cause unspecified security impacts.
35) Protection mechanism failure (CVE-ID: CVE-2026-92075)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security mitigations.
The vulnerability exists due to a protection mechanism failure in the Networking component when processing input. A remote attacker can process input to bypass security mitigations.
36) Protection mechanism failure (CVE-ID: CVE-2026-92074)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security mitigations.
The vulnerability exists due to a protection mechanism failure in the Popup Blocker component when processing input. A remote attacker can process input to bypass security mitigations.
37) Input validation error (CVE-ID: CVE-2026-92073)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an unspecified flaw in the Enterprise Policies component when processing input. A remote attacker can process input to escalate privileges.
38) Input validation error (CVE-ID: CVE-2026-92072)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause unspecified security impacts.
The vulnerability exists due to incorrect boundary conditions in the Safe Browsing component when processing input. A remote attacker can process input to cause unspecified security impacts.
39) Improper privilege management (CVE-ID: CVE-2026-92015)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the WebExtensions component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
40) Use-after-free (CVE-ID: CVE-2026-92027)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: Streams component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
41) Use-after-free (CVE-ID: CVE-2026-92025)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: Navigation component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
42) Use-after-free (CVE-ID: CVE-2026-92024)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the SVG component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
43) Use-after-free (CVE-ID: CVE-2026-92023)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the XML component when parsing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
44) Use-after-free (CVE-ID: CVE-2026-92022)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: HTML Parser component when parsing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
45) Input validation error (CVE-ID: CVE-2026-92020)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: WebRender component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
46) Protection mechanism failure (CVE-ID: CVE-2026-92019)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to insufficient mitigation enforcement in the Remote Settings Client component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to bypass a security mitigation.
User interaction is required to visit the crafted website.
47) Protection mechanism failure (CVE-ID: CVE-2026-92018)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to improper sandbox isolation in the DOM: Core & HTML component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to escape the browser sandbox.
User interaction is required to visit the crafted website.
48) Improper privilege management (CVE-ID: CVE-2026-92017)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the DOM: Service Workers component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
49) Use-after-free (CVE-ID: CVE-2026-92028)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
50) Input validation error (CVE-ID: CVE-2026-92014)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
51) Input validation error (CVE-ID: CVE-2026-92013)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
52) Input validation error (CVE-ID: CVE-2026-92012)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
53) Input validation error (CVE-ID: CVE-2026-92011)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
54) Input validation error (CVE-ID: CVE-2026-92010)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
55) Input validation error (CVE-ID: CVE-2026-92009)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
56) Input validation error (CVE-ID: CVE-2026-92008)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
57) Input validation error (CVE-ID: CVE-2026-92007)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
58) Input validation error (CVE-ID: CVE-2026-92035)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing input. A remote attacker can process input to escape the sandbox.
59) Use-after-free (CVE-ID: CVE-2026-92046)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the Graphics component when processing input. A remote attacker can process input to cause memory corruption.
60) Input validation error (CVE-ID: CVE-2026-92045)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the WebRTC component when processing input. A remote attacker can process input to escape the sandbox.
61) Information disclosure (CVE-ID: CVE-2026-92044)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an unspecified flaw in the Networking: HTTP component when processing input. A remote attacker can process input to disclose sensitive information.
62) Input validation error (CVE-ID: CVE-2026-92043)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video component when processing input. A remote attacker can process input to escalate privileges.
63) Race condition (CVE-ID: CVE-2026-92042)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause unspecified security impacts.
The vulnerability exists due to a race condition in the DOM: Content Processes component when processing input. A remote attacker can process input to cause unspecified security impacts.
64) Protection mechanism failure (CVE-ID: CVE-2026-92041)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security mitigations.
The vulnerability exists due to a protection mechanism failure in the DOM: Networking component when processing input. A remote attacker can process input to bypass security mitigations.
65) Protection mechanism failure (CVE-ID: CVE-2026-92039)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security mitigations.
The vulnerability exists due to a protection mechanism failure in the DOM: Notifications component when processing input. A remote attacker can process input to bypass security mitigations.
66) Protection mechanism failure (CVE-ID: CVE-2026-92038)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass security mitigations.
The vulnerability exists due to a protection mechanism failure in the Remote Settings Client component when processing input. A remote attacker can process input to bypass security mitigations.
67) Input validation error (CVE-ID: CVE-2026-92006)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.
User interaction is required to visit the crafted website.
68) NULL pointer dereference (CVE-ID: CVE-2026-92032)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to an invalid pointer in the Graphics component when processing web content. A remote attacker can trigger the invalid pointer condition to escape the sandbox.
69) Information disclosure (CVE-ID: CVE-2026-92031)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to information disclosure in the Graphics: ImageLib component when processing web content. A remote attacker can process web content with the affected component to disclose sensitive information.
70) Protection mechanism failure (CVE-ID: CVE-2026-92030)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a mitigation.
The vulnerability exists due to a protection mechanism failure in the DOM: Copy & Paste and Drag & Drop component when processing web content. A remote attacker can exploit the protection mechanism failure to bypass a mitigation.
71) Use-after-free (CVE-ID: CVE-2026-92026)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Networking component when processing web content. A remote attacker can trigger the use-after-free condition to execute arbitrary code.
72) Use-after-free (CVE-ID: CVE-2026-92021)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript Engine: JIT component when processing web content. A remote attacker can trigger the use-after-free condition to execute arbitrary code.
73) Use-after-free (CVE-ID: CVE-2026-92016)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Disability Access APIs component when processing web content. A remote attacker can trigger the use-after-free condition to execute arbitrary code.
74) Use-after-free (CVE-ID: CVE-2026-92005)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Audio/Video: Web Codecs component when processing web content. A remote attacker can trigger the use-after-free condition to execute arbitrary code.
75) Use-after-free (CVE-ID: CVE-2026-92029)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the SVG component when rendering web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
Remediation
Install update from vendor's website.
References
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068438
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060220
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059196
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058790
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058664
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058018
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057990
- https://bugzilla.mozilla.org/show_bug.cgi?id=2054670
- https://bugzilla.mozilla.org/show_bug.cgi?id=2027336
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068442
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061231
- https://bugzilla.mozilla.org/show_bug.cgi?id=2065646
- https://bugzilla.mozilla.org/show_bug.cgi?id=2065346
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063652
- https://bugzilla.mozilla.org/show_bug.cgi?id=2062551
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061503
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061499
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061295
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061235
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058093
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068460
- https://bugzilla.mozilla.org/show_bug.cgi?id=2024248
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061387
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041758
- https://bugzilla.mozilla.org/show_bug.cgi?id=2055737
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061393
- https://bugzilla.mozilla.org/show_bug.cgi?id=2047339
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060295
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068416
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059021
- https://bugzilla.mozilla.org/show_bug.cgi?id=2067531
- https://bugzilla.mozilla.org/show_bug.cgi?id=2066736
- https://bugzilla.mozilla.org/show_bug.cgi?id=2064601
- https://bugzilla.mozilla.org/show_bug.cgi?id=2064026
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063814
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063539
- https://bugzilla.mozilla.org/show_bug.cgi?id=2062527
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061257
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-91/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060235
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068433
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068361
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068354
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068342
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068059
- https://bugzilla.mozilla.org/show_bug.cgi?id=2066329
- https://bugzilla.mozilla.org/show_bug.cgi?id=2065636
- https://bugzilla.mozilla.org/show_bug.cgi?id=2064287
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061777
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068440
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060000
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058078
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058069
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058068
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058067
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058066
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058065
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058064
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061245
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058618
- https://bugzilla.mozilla.org/show_bug.cgi?id=2054622
- https://bugzilla.mozilla.org/show_bug.cgi?id=2051466
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050150
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049342
- https://bugzilla.mozilla.org/show_bug.cgi?id=2029482
- https://bugzilla.mozilla.org/show_bug.cgi?id=2001265
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068952
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057121
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068437
- https://bugzilla.mozilla.org/show_bug.cgi?id=2067971
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058417
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068378
- https://bugzilla.mozilla.org/show_bug.cgi?id=2067208
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061327
- https://bugzilla.mozilla.org/show_bug.cgi?id=2056051
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068445