Description
Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Published: 2026-09-15
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox Escape
Action: Immediate Patch
AI Analysis

Impact

This vulnerability permits a sandbox escape in the DOM Core and HTML components of Mozilla browsers and email client. An attacker who can supply or influence HTML or DOM content—such as a malicious web page or compromised email attachment—can potentially bypass the sandbox restrictions that normally isolate such content from the rest of the system, leading to execution of arbitrary code or the compromise of data integrity and confidentiality.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are affected. Versions prior to Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3 are vulnerable. Upgrading to the stated release numbers removes the flaw.

Risk and Exploitability

The EPSS score of 0.0016 (less than 1%) indicates a very low currently observed exploitation probability, but the CVSS score of 9.6 and the nature of a sandbox escape remain sufficient to warrant concern. The likely attack vector is a malicious web page or email attachment that delivers crafted DOM content, which an attacker can use to escape the browser or email client sandbox and potentially execute code or access sensitive information. This vulnerability is not listed in CISA KEV, indicating no known widespread exploitation at the time of reporting.

Generated by OpenCVE AI on September 20, 2026 at 17:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to at least version 156 or the ESR releases 115.41, 140.16, or 153.3, and upgrade Mozilla Thunderbird to at least version 156, 140.16, or 153.3; the patch applies to both products and revokes the sandbox escape flaw.
  • If immediate upgrade is not possible, disable or remove extensions and plugins that inject arbitrary HTML, reduce the trust level of supplied HTML by configuring content security policies, and isolate the browser or email client in a highly restricted or virtualized environment to limit the impact of a sandbox escape.
  • As a temporary measure, block outbound traffic to known malicious domains, enforce strict domain whitelisting, and monitor for suspicious activity that may indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4781-1 firefox-esr security update
Debian DLA Debian DLA DLA-4782-1 thunderbird security update
Debian DSA Debian DSA DSA-6501-1 firefox-esr security update
Debian DSA Debian DSA DSA-6503-1 thunderbird security update
History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-791
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, and Thunderbird 140.16. Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
References

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3. Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, and Thunderbird 140.16.
References

Tue, 15 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.
Title Sandbox escape in the DOM: Core & HTML component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-20T00:15:48.795Z

Reserved: 2026-09-15T12:33:37.558Z

Link: CVE-2026-92018

cve-icon Vulnrichment

Updated: 2026-09-20T00:15:43.296Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T13:16:51.540

Modified: 2026-09-20T01:16:34.680

Link: CVE-2026-92018

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T12:33:38Z

Links: CVE-2026-92018 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:30:18Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-791

    Incomplete Filtering of Special Elements