CVE-2026-84117
massPrivilege Escalation in Firefox for Android (fixed in Firefox 155)
Mozilla has fixed a privilege escalation flaw in Firefox for Android, tracked as CVE-2026-84117, classified as improper access control (CWE-284) and rated high severity at CVSS 8.8. According to the CVSS vector, the flaw is reachable over the network, requires no privileges, and requires user interaction, meaning an attacker would need to lure the user into some action (the disclosure does not specify the exact trigger mechanism). A successful exploit grants the attacker elevated privileges with high impact on confidentiality, integrity and availability on the affected device. All Firefox for Android users running builds earlier than Firefox 155 are affected; desktop Firefox and other products are not listed in this disclosure. There is currently no public proof of concept, no CISA KEV entry, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days, so no exploitation is known.
What to do: Update Firefox for Android to version 155 or later, which can be done via the Google Play store or by enabling automatic app updates, and verify the installed version in the app's settings. No workarounds or in-the-wild exploitation are known, but given the high severity score the update should be applied promptly, especially for users handling sensitive accounts on mobile.
| Mozilla Firefox for Android (Firefox Mobile) | All versions prior to Firefox 155 (fixed in Firefox 155) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
- Vendors
- mozilla
- Products
- firefox mobile
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.