VDB
CVE-2026-92045
CVE-2026-92045
PUBLISHED
Reported by mozilla · Published September 15, 2026
Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
EPSS 0.15% · 4.7th percentile
Risk Scores
EPSS Score
0.15%
4.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 153.3, 156 |
| Mozilla | Thunderbird | 153.3, 156 |
| Mozilla | Firefox | 153.3, 156, 153.3 |
| Mozilla | Thunderbird | 153.3, 156, 156 |
Timeline
- Sep 15, 2026 Coalition ESS Score
- Sep 15, 2026 CVE Published
- Sep 16, 2026 EPSS Score
- Sep 16, 2026 CVE Updated