Protection mechanism failure in Mozilla products - CVE-2026-92018
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to improper sandbox isolation in the DOM: Core & HTML component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to escape the browser sandbox.
User interaction is required to visit the crafted website.
Affected software
Firefox ESR
Firefox for Android
How to mitigate CVE-2026-92018
Firefox for Android - update to 156.0
Firefox ESR - addressed in versions 115.41.0, 140.16.0, 153.3.0