CVE-2026-92050: firefox: thunderbird: Sandbox escape due to race condition in the XPConnect component

Severity: Critical

CVSS Score: 9.1

Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.