Description
Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Published: 2026-09-15
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape
Action: Immediate Patch
AI Analysis

Impact

The flaw arises from an invalid pointer reference in the Graphics component, which can be triggered by processing malformed or crafted graphics data. This memory corruption leads to a sandbox escape, allowing code to run with the same privileges as the host application. The vulnerability is associated with buffer overflow, null reference dereference, and out‑of‑bounds write weaknesses.

Affected Systems

Affected Mozilla releases include Firefox up to version 155, Firefox ESR 140.15/153.2, Thunderbird up to version 155, and Thunderbird ESR 140.15. The issue was fixed in Firefox 156, ESR 140.16, and ESR 153.3, as well as in Thunderbird 156, ESR 140.16, and ESR 153.3.

Risk and Exploitability

The EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 9.6 denotes a critical risk level. An attacker would most likely exploit the flaw by delivering a crafted graphics file or otherwise forcing the application to render untrusted visual content, thereby escaping the sandbox. Because the attack requires controlled rendering inside the sandbox, it is less easily achieved from a remote position but still feasible for local or privileged adversaries.

Generated by OpenCVE AI on September 21, 2026 at 18:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox to a patched version (156+ or ESR 140.16+, ESR 153.3+).
  • Upgrade Thunderbird to a patched version (156+ or ESR 140.16+, ESR 153.3+). If an upgrade cannot be performed immediately, configure the application to disable or sandbox rendering of untrusted graphics content to reduce the attack surface.
  • Continuously monitor application behavior for sandbox violations and apply the latest security advisories from Mozilla as soon as they are released.

Generated by OpenCVE AI on September 21, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4781-1 firefox-esr security update
Debian DLA Debian DLA DLA-4782-1 thunderbird security update
Debian DSA Debian DSA DSA-6501-1 firefox-esr security update
Debian DSA Debian DSA DSA-6503-1 thunderbird security update
History

Mon, 05 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 23 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-476
CWE-787

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, and Thunderbird 140.16. Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
References

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, and Firefox ESR 153.3. Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, and Thunderbird 140.16.
References

Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, and Firefox ESR 153.3.
Title Sandbox escape due to invalid pointer in the Graphics component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T16:59:01.246Z

Reserved: 2026-09-15T12:33:52.430Z

Link: CVE-2026-92032

cve-icon Vulnrichment

Updated: 2026-09-21T16:58:37.164Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:54.440

Modified: 2026-10-05T18:01:31.197

Link: CVE-2026-92032

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:33:52Z

Links: CVE-2026-92032 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:00:08Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-476

    NULL Pointer Dereference