Vulnerability Description
Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061387
- https://www.mozilla.org/security/advisories/mfsa2026-90/
- https://www.mozilla.org/security/advisories/mfsa2026-94/
FAQ
What is CVE-2026-92050?
CVE-2026-92050 is a documented vulnerability. Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
How severe is CVE-2026-92050?
CVSS scoring is not yet available for CVE-2026-92050. Check NVD for updates.
Is there a patch for CVE-2026-92050?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.