ZeroHour

CVE-2026-92017

mass

Privilege Escalation in Firefox Service Workers — Fixed in Firefox 156 and ESR Releases

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92017 is a privilege escalation vulnerability (CWE-269) in the Service Workers component of Firefox's DOM implementation. Exploitation is network-based, requires no attacker privileges, but does require user interaction — meaning a victim must be lured to malicious or compromised web content that abuses service worker handling. A successful attack yields high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8), letting the attacker operate with privileges beyond what ordinary web content should hold. All users of Firefox release builds before 156 and of the ESR branches before 115.41, 140.16, and 153.3 are affected. No public proof-of-concept exists and the flaw is not in the CISA KEV catalog, so no exploitation in the wild has been reported to date.

What to do: Update immediately to Firefox 156, or to the patched ESR release matching your deployment (ESR 115.41, ESR 140.16, or ESR 153.3). Enterprise and org administrators should inventory which ESR branch is in use and push the corresponding build before older branches fall out of support. Verify the running version via the browser's about:support page or update settings, and ensure automatic updates are enabled for end users.

Affected
Mozilla Firefoxrelease builds before Firefox 156
Mozilla Firefox ESR 115before 115.41
Mozilla Firefox ESR 140before 140.16
Mozilla Firefox ESR 153before 153.3
Estimated exposure
mass≈ hundreds of millions of Firefox users (every pre-patch install is vulnerable pending update) — Mozilla's Firefox desktop browser has a global installed base on the order of hundreds of millions of users, and all versions below the four fixed releases listed above are affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.