Description
Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability is a site isolation flaw in the Reader Mode component that can allow an attacker to bypass the separation between browsing contexts and potentially read data that should be protected.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are affected. The fix is available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Risk and Exploitability

The CVSS score is 5.4. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. A likely attack would require the use of Reader Mode and would target a user who enables the feature or visits a site that automatically triggers it. Because no real-world exploitation is reported and the component is not widely exposed, the risk of deployment is low but the impact of a successful attack could involve unauthorized access to data from a browsing context.

Generated by OpenCVE AI on September 22, 2026 at 17:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 156 or later, or at least ESR 153.3, to apply the fix.
  • Upgrade Thunderbird to version 156 or later, to apply the fix.
  • If an update is not possible, disable the Reader Mode feature in the application settings to prevent the vulnerability from being exploited.

Generated by OpenCVE AI on September 22, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Sun, 20 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-653
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Site isolation issue in the Reader Mode component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-22T15:29:17.764Z

Reserved: 2026-09-15T12:34:29.473Z

Link: CVE-2026-92068

cve-icon Vulnrichment

Updated: 2026-09-22T15:28:40.295Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:01.513

Modified: 2026-10-05T19:41:33.873

Link: CVE-2026-92068

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:29Z

Links: CVE-2026-92068 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T18:00:17Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-653

    Improper Isolation or Compartmentalization