CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
Published Sep 15, 2026
·Updated
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Affected Software
2 affected components
Mozilla Firefox<156
Mozilla Firefox ESR<153.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 156 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 153.3
Event History
Sep 15, 2026
CVE Published
via MITRE·12:34 PM
Data Sourced
via MITRE·12:34 PM
Description
Frequently Asked Questions
1
Which Firefox releases include the fix?
The vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
2
How can I determine whether my installation has the fix?
Check the installed Firefox version. Systems running Firefox 156 or Firefox ESR 153.3 include the fix.