ZeroHour

CVE-2026-84117

mass

Privilege Escalation in Firefox for Android (fixed in Firefox 155)

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

Mozilla has fixed a privilege escalation flaw in Firefox for Android, tracked as CVE-2026-84117, classified as improper access control (CWE-284) and rated high severity at CVSS 8.8. According to the CVSS vector, the flaw is reachable over the network, requires no privileges, and requires user interaction, meaning an attacker would need to lure the user into some action (the disclosure does not specify the exact trigger mechanism). A successful exploit grants the attacker elevated privileges with high impact on confidentiality, integrity and availability on the affected device. All Firefox for Android users running builds earlier than Firefox 155 are affected; desktop Firefox and other products are not listed in this disclosure. There is currently no public proof of concept, no CISA KEV entry, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days, so no exploitation is known.

What to do: Update Firefox for Android to version 155 or later, which can be done via the Google Play store or by enabling automatic app updates, and verify the installed version in the app's settings. No workarounds or in-the-wild exploitation are known, but given the high severity score the update should be applied promptly, especially for users handling sensitive accounts on mobile.

Affected
Mozilla Firefox for Android (Firefox Mobile)All versions prior to Firefox 155 (fixed in Firefox 155)
Estimated exposure
masstens of millions of Android users (Firefox for Android has 100M+ Google Play installs) — Firefox for Android's very large installed base — 100M+ downloads on Google Play and tens of millions of active users — puts this in the mass category even though only users on pre-155 builds are affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

Vendors
mozilla
Products
firefox mobile
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.