Description
Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape
Action: Patch Now
AI Analysis

Impact

This vulnerability arises from incorrect boundary conditions in the WebRTC component, which allows an attacker to escape the application sandbox. The flaw manifests as a boundary‑checking bug that can be triggered by specially crafted data received through WebRTC. Escaping the sandbox can enable malicious code to run with the privileges of the browser or mail client, undermining the security model of the process isolation.

Affected Systems

Mozilla Firefox versions older than 156 and ESR releases before 153.3, as well as Mozilla Thunderbird versions older than 156 and ESR releases before 153.3 are affected. These releases contain the vulnerable WebRTC implementation and must be upgraded to the patched versions to eliminate the flaw.

Risk and Exploitability

The CVSS score of 9.6 indicates a high severity. The EPSS score of <1% suggests that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation via network traffic processed by WebRTC, requiring the presence of the vulnerable component and a remote connection. While the risk is high, the potential to escape a sandbox and undermine process isolation makes it a high‑impact flaw should an attacker find a way to trigger it.

Generated by OpenCVE AI on September 21, 2026 at 19:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Firefox 156 (or ESR 153.3) and Thunderbird 156 (or ESR 153.3) to remove the boundary check bug
  • Disable or block WebRTC functionality if an upgrade cannot be performed immediately
  • Monitor Mozilla security advisories and maintain an inventory of installed software versions to ensure timely patching

Generated by OpenCVE AI on September 21, 2026 at 19:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-264

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-653
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-264

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Sandbox escape due to incorrect boundary conditions in the WebRTC component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T17:34:22.070Z

Reserved: 2026-09-15T12:34:05.844Z

Link: CVE-2026-92045

cve-icon Vulnrichment

Updated: 2026-09-21T17:34:03.536Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:55.973

Modified: 2026-10-05T17:50:38.797

Link: CVE-2026-92045

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:34:06Z

Links: CVE-2026-92045 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:45:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-653

    Improper Isolation or Compartmentalization