CVE-2026-92017
massPrivilege Escalation in Firefox Service Workers — Fixed in Firefox 156 and ESR Releases
CVE-2026-92017 is a privilege escalation vulnerability (CWE-269) in the Service Workers component of Firefox's DOM implementation. Exploitation is network-based, requires no attacker privileges, but does require user interaction — meaning a victim must be lured to malicious or compromised web content that abuses service worker handling. A successful attack yields high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8), letting the attacker operate with privileges beyond what ordinary web content should hold. All users of Firefox release builds before 156 and of the ESR branches before 115.41, 140.16, and 153.3 are affected. No public proof-of-concept exists and the flaw is not in the CISA KEV catalog, so no exploitation in the wild has been reported to date.
What to do: Update immediately to Firefox 156, or to the patched ESR release matching your deployment (ESR 115.41, ESR 140.16, or ESR 153.3). Enterprise and org administrators should inventory which ESR branch is in use and push the corresponding build before older branches fall out of support. Verify the running version via the browser's about:support page or update settings, and ensure automatic updates are enabled for end users.
| Mozilla Firefox | release builds before Firefox 156 |
| Mozilla Firefox ESR 115 | before 115.41 |
| Mozilla Firefox ESR 140 | before 140.16 |
| Mozilla Firefox ESR 153 | before 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.