CVE-2026-92066: Sandbox escape in the Profile Backup component
Published Sep 15, 2026
·Updated
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156.
Affected Software
1 affected component
Mozilla Firefox<156
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 156
Event History
Sep 15, 2026
CVE Published
via MITRE·12:34 PM
Data Sourced
via MITRE·12:34 PM
Description
Frequently Asked Questions
1
Which Firefox versions need to be updated?
The vulnerability was fixed in Firefox 156. Versions before the fixed release should be treated as needing an update based on the available information.
2
What component is involved?
The issue is in Firefox's Profile Backup component. The provided information does not specify exploitation prerequisites, affected configurations, or temporary mitigations.