ZeroHour

CVE-2026-92033

mass

Privilege Escalation in Mozilla Firefox for Android (Fixed in Firefox 156)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92033 is a privilege escalation vulnerability (CWE-269, improper privilege management) in Firefox for Android, patched in Firefox 156 and rated High severity (CVSS 8.8). The CVSS vector indicates it is exploited over the network with low attacker complexity and no privileges required, but user interaction is required — meaning a victim would typically need to be lured into an action such as visiting a crafted page or confirming a prompt for the attack to succeed. A successful exploit could allow an attacker to escape intended permission boundaries within the browser, with high impact on confidentiality, integrity, and availability of data accessible to Firefox. All users of Firefox for Android on versions prior to 156 are affected. No public proof-of-concept exists and no exploitation in the wild has been reported; the flaw is not on the CISA Known Exploited Vulnerabilities catalog.

What to do: Update Firefox for Android to version 156 or later immediately via Google Play or your organization's app store, and verify the version under Settings > About Firefox. Organizations managing Android fleets should confirm the updated build is pushed through MDM and check for any unusually broad Android browser permissions granted on managed devices. Because exploitation requires user interaction, remind users to be cautious with unexpected prompts and links until the update is confirmed.

Affected
Mozilla Firefox for AndroidAll versions prior to 156 (fixed in Firefox 156)
Estimated exposure
massTens of millions of Android devices (Firefox for Android has 100M+ downloads on Google Play) — Firefox for Android's Google Play listing shows over 100 million downloads with a global Android user base plausibly in the tens of millions, nearly all of whom would be exposed until patched to version 156.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.