CVE-2026-4692: Sandbox escape in the Responsive Design Mode component
Sandbox escape in the Responsive Design Mode component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.
Other sources
Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.34 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.9 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 149 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.34 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.9 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 149 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.9
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-4684
- CVE-2026-4685
- CVE-2026-4686
- CVE-2026-4687
- CVE-2026-4688
- CVE-2026-4689
- CVE-2026-4690
- CVE-2026-4691
- CVE-2026-4692
- CVE-2026-4693
- CVE-2026-4694
- CVE-2026-4695
- CVE-2026-4696
- CVE-2026-4697
- CVE-2026-4698
- CVE-2026-4699
- CVE-2026-4700
- CVE-2026-4701
- CVE-2026-4722
- CVE-2026-4702
- CVE-2026-4723
- CVE-2026-4724
- CVE-2026-4704
- CVE-2026-4705
- CVE-2026-4706
- CVE-2026-4707
- CVE-2026-4708
- CVE-2026-4709
- CVE-2026-4710
- CVE-2026-4711
- CVE-2026-4725
- CVE-2026-4712
- CVE-2026-4713
- CVE-2026-4714
- CVE-2026-4715
- CVE-2026-4716
- CVE-2026-4717
- CVE-2026-4726
- CVE-2025-59375
- CVE-2026-4727
- CVE-2026-4728
- CVE-2026-4718
- CVE-2026-4719
- CVE-2026-4720
- CVE-2026-4729
- CVE-2026-4721
- CVE-2026-3889
- CVE-2026-4371
Frequently Asked Questions
What is the severity of CVE-2026-4692?
The severity of CVE-2026-4692 is critical with a CVSS score of 10.
How do I fix CVE-2026-4692?
To fix CVE-2026-4692, update to Firefox version 149, Firefox ESR version 115.34, Firefox ESR 140.9, or Thunderbird 149.
Which software is affected by CVE-2026-4692?
CVE-2026-4692 affects Mozilla Firefox versions below 149, Firefox ESR versions below 115.34, and Thunderbird versions below 149.
What is the nature of the vulnerability in CVE-2026-4692?
CVE-2026-4692 is a sandbox escape vulnerability in the Responsive Design Mode component.
When was CVE-2026-4692 published?
CVE-2026-4692 was published on March 24, 2026.