ZeroHour

CVE-2026-92015

mass

Privilege Escalation in Firefox WebExtensions (fixed in Firefox 156 / ESR 115.41, 140.16, 153.3)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92015 is a privilege escalation flaw (CWE-269, improper privilege management) in the WebExtensions component of Mozilla Firefox, scored CVSS 3.1 at 8.8 (high). The bug allows an attacker to elevate privileges within the browser context, with network access, low attack complexity, no privileges required, but user interaction required — meaning victims are typically lured into an action such as installing or interacting with a crafted extension or page. Successful exploitation can yield high impacts to confidentiality, integrity, and availability within the browser, potentially exposing browsing data, session cookies, or enabling further compromise of the user's context. All users of Firefox releases prior to the fixed versions are affected, including users of the enterprise-focused ESR branches, which hold older vulnerable code bases for extended support periods. No public proof of concept is known and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Update to Firefox 156 or Firefox ESR 115.41, ESR 140.16, or ESR 153.3 depending on your branch, and confirm ESR deployments are pinned to the patched point release since enterprises on stale ESR builds remain exposed. Audit installed extensions and browser policies for anything unusual, and watch for signs of extension-based compromise such as unexpected permission grants or injected content.

Affected
Mozilla Firefoxbefore 156
Mozilla Firefox ESRbefore 115.41
Mozilla Firefox ESRbefore 140.16
Mozilla Firefox ESRbefore 153.3
Estimated exposure
mass≈100-200 million Firefox users (Firefox holds roughly 6% of desktop browser market share), including large enterprise ESR deployments — Estimated from Firefox's global desktop browser market share (public StatCounter-type figures around 6% of a ~1.5B-user desktop base), plus widespread enterprise use of the ESR branches that require separate patches.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.