Protection mechanism failure in Mozilla products - CVE-2026-92019
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to insufficient mitigation enforcement in the Remote Settings Client component when processing web content. A remote attacker can trick the victim into visiting a specially crafted website to bypass a security mitigation.
User interaction is required to visit the crafted website.
Affected software
Firefox ESR
Firefox for Android
How to mitigate CVE-2026-92019
Firefox for Android - update to 156.0
Firefox ESR - addressed in versions 115.41.0, 140.16.0, 153.3.0