Description
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape leading to potential code execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability is caused by incorrect boundary checks in the Widget: Win32 component, which can result in a sandbox escape. This flaw would allow an attacker to execute code with the privileges of the offending application. Based on the description, the primary risk is the ability to run arbitrary code in the context of Firefox or Thunderbird, potentially compromising the user’s data or system.

Affected Systems

Mozilla products – Firefox versions earlier than 156 and ESR 153.3, and Thunderbird versions earlier than 156 are affected. The security advisory states that the issue was fixed in those releases.

Risk and Exploitability

The EPSS score of <1% indicates a very low likelihood of exploitation, and the CVSS score of 8.8 places the vulnerability in the high severity range. Although the flaw is not listed in CISA’s KEV catalog, the potential impact of sandbox escape is significant. The likely attack vector, inferred from the description, involves an attacker supplying a malicious Widget: Win32 file to the application, which is realistic in environments where user‑supplied widgets are allowed. Thus, while exploitation probability remains low, the impact warrants precautionary action.

Generated by OpenCVE AI on September 21, 2026 at 20:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch for Firefox 156 or ESR 153.3 and above, or Thunderbird 156 or ESR 153.3 and above.
  • If an update cannot be applied immediately, disable or restrict Widget: Win32 support via policy or configuration to prevent loading potentially malicious widgets.
  • Verify that all buffer boundary checks in the Widget: Win32 component are secure and follow best practices for input validation, addressing CWE-119.

Generated by OpenCVE AI on September 21, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-21T18:08:08.142Z

Reserved: 2026-09-15T12:34:26.423Z

Link: CVE-2026-92065

cve-icon Vulnrichment

Updated: 2026-09-21T18:06:37.275Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:01.147

Modified: 2026-10-05T18:57:23.457

Link: CVE-2026-92065

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:26Z

Links: CVE-2026-92065 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:00:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write