External risk intelligence

Firefox Thunderbird WebRTC Sandbox Escape

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-92045

This vulnerability exists within the WebRTC component of client-side software (web browsers and email clients). It requires a user to navigate to malicious content, and it is not an internet-facing service, edge gateway, or server-side application that is reachable by an attacker without specific user interaction.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the WebRTC component of certain Mozilla products, specifically Firefox and Thunderbird. This issue allows for a sandbox escape, which could potentially lead to significant compromise of affected systems. The main concern is confirming relevance and exposure.

  • Code flaw allows bypassing security isolation.
  • Impacts user interactions with web and email.
  • Confirming relevance and exposure is key.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious website or opening a specially crafted email attachment. This would expose the vulnerable WebRTC component within the user's browser or email client. If successful, the attacker could then potentially escape the software's sandbox, leading to further compromise.

  • No specific access required.
  • Triggered by user interaction with malicious content.
  • Allows sandbox escape and further compromise.

Live Threat

Current exploitation, exposure, and threat context

A sandbox escape vulnerability in the WebRTC component could allow an attacker to affect the behavior of the affected application when the user interacts with specially crafted content. This could lead to unauthorized access to system resources beyond the intended sandbox boundaries.

  • System and user data could be accessed.
  • Malicious content could trigger the escape.
  • Application behavior could be modified.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the WebRTC component of Firefox and Thunderbird requires a user to interact with malicious content, making it primarily an end-user or endpoint security concern. The first step is to identify all deployed instances of these applications, confirm their reachability, and then assess business criticality to prioritize remediation efforts with the accountable owners.

  • Identify application owners and endpoints.
  • Verify user interaction and exposure.
  • Plan targeted updates or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WebRTC component in Firefox and Thunderbird?

WebRTC, or Web Real-Time Communication, is a technology embedded in Firefox and Thunderbird that enables direct audio, video, and data exchange between browsers or applications. It is what powers features like in-browser video conferencing and real-time data sharing. Because it handles complex, incoming data streams from the internet, it must be carefully isolated from the rest of your computer's operating system to prevent malicious code from jumping out of the browser.

How does CVE-2026-92045 cause a sandbox escape?

This vulnerability is classified as CWE-119, which relates to improper restriction of operations within memory boundaries. In this specific case, the WebRTC component fails to correctly calculate or check boundaries when processing data. This memory safety flaw allows an attacker to bypass the 'sandbox'—the security wall designed to keep the browser isolated from your computer—potentially giving them the ability to run unauthorized commands on the underlying system.

Do I need to be actively using a video call to trigger this bug?

No. The flaw is triggered when the application processes specially crafted content. While WebRTC is used for calls, an attacker does not need to initiate a live video session with you. Simply navigating to a malicious website or opening a compromised email attachment can cause the browser or mail client to process the harmful data, potentially triggering the escape without any active call in progress.

Is my system at risk if it isn't an internet-facing server?

According to Halo Surface Signal, this vulnerability is considered 'Very unlikely' to be exploited through standard network scanning because it exists in client-side software, not an internet-facing server. The risk is not based on your system's network exposure, but rather on user behavior. Because it requires a user to interact with malicious content, the primary risk is to endpoint devices where users frequently browse the web or check email.

What should I do to protect my systems from this vulnerability?

The most effective response is to update your software to the corrected versions. Ensure all instances of Firefox are updated to version 156 or 153.3 ESR, and Thunderbird to 156 or 153.3. Beyond updating, start by identifying where these applications are installed across your environment. Since the risk depends on user interaction, focus on keeping these applications patched on all end-user workstations and laptops.

References