Description
Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
In plain language
AI Act nowThis is a serious flaw in Firefox and Thunderbird that a malicious webpage or message could use to take control of a computer if the user opens it; update to a fixed version now.
A user-assisted, unauthenticated network attack can exploit an out-of-bounds memory error (CWE-120) in the WebRender graphics component to escalate privileges and potentially achieve full system compromise.
What to do now
- Check the installed version of Firefox or Thunderbird on every business computer.
- Update Firefox to 115.41, 140.16, 153.3, or 156 or later, matching your supported release branch.
- Update Thunderbird to 140.16, 153.3, or 156 or later, matching your supported release branch.
- Until updated, tell staff not to open unexpected links, web pages, or email content.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-92020 and every CVE in our database. Create a free account — no credit card required.
Create Free Account