Description
Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Published: 2026-09-15
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape potentially allowing code execution or privilege escalation
Action: Patch Now
AI Analysis

Impact

This vulnerability involves incorrect boundary conditions in the Security: Process Sandboxing component, enabling a potential escape from the sandbox. The flaw could allow malicious content to gain elevated privileges or execute arbitrary code, compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

The issue affects Mozilla Firefox and Thunderbird. All versions released before Firefox 156 and Thunderbird 156 are vulnerable, and the flaw was fixed in those releases.

Risk and Exploitability

Because no EPSS score or KEV listing is available, the current exploitation likelihood is not quantified. However, the nature of the flaw—a sandbox boundary violation—suggests that an attacker could exploit it to bypass process isolation, potentially leading to a complete compromise of the host if they can supply malicious content or files to the application. The absence of a publicly known exploit does not negate the risk, and administrators should treat it as a high severity precaution.

Generated by OpenCVE AI on September 16, 2026 at 04:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 156 or later, or Thunderbird 156 or later
  • If an upgrade cannot be applied immediately, disable or limit sandboxing features for the affected products, noting this may degrade security posture
  • Implement monitoring of inter-process communication for abnormal activity patterns that could indicate a sandbox escape attempt

Generated by OpenCVE AI on September 16, 2026 at 04:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-403
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Wed, 16 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
CWE-788

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156. Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156.
Title Incorrect boundary conditions in the Security: Process Sandboxing component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-15T20:01:58.036Z

Reserved: 2026-09-15T12:34:22.367Z

Link: CVE-2026-92061

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T13:17:00.653

Modified: 2026-09-16T19:34:05.910

Link: CVE-2026-92061

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:22Z

Links: CVE-2026-92061 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T04:15:18Z

Weaknesses
  • CWE-403

    Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')

  • CWE-787

    Out-of-bounds Write

  • CWE-788

    Access of Memory Location After End of Buffer