CWE-368
CVEs classified under CWE-368, newest first.
2 CVEsRSS
CVE-2026-92050Critical· 9.1⚖ disputedSandbox escape due to race condition in the XPConnect component
Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
▾ MidnightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92055High· 8.8⚖ disputedPrivilege escalation in the DevTools component
Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
▾ TwilightMozilla · FirefoxEPSS 0.24%via NVD