Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
https://www.mozilla.org/security/advisories/mfsa2026-94/
https://www.mozilla.org/security/advisories/mfsa2026-90/