CVE-2026-92033
massPrivilege Escalation in Mozilla Firefox for Android (Fixed in Firefox 156)
CVE-2026-92033 is a privilege escalation vulnerability (CWE-269, improper privilege management) in Firefox for Android, patched in Firefox 156 and rated High severity (CVSS 8.8). The CVSS vector indicates it is exploited over the network with low attacker complexity and no privileges required, but user interaction is required — meaning a victim would typically need to be lured into an action such as visiting a crafted page or confirming a prompt for the attack to succeed. A successful exploit could allow an attacker to escape intended permission boundaries within the browser, with high impact on confidentiality, integrity, and availability of data accessible to Firefox. All users of Firefox for Android on versions prior to 156 are affected. No public proof-of-concept exists and no exploitation in the wild has been reported; the flaw is not on the CISA Known Exploited Vulnerabilities catalog.
What to do: Update Firefox for Android to version 156 or later immediately via Google Play or your organization's app store, and verify the version under Settings > About Firefox. Organizations managing Android fleets should confirm the updated build is pushed through MDM and check for any unusually broad Android browser permissions granted on managed devices. Because exploitation requires user interaction, remind users to be cautious with unexpected prompts and links until the update is confirmed.
| Mozilla Firefox for Android | All versions prior to 156 (fixed in Firefox 156) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.