CVE-2026-92047
massPrivilege Escalation in Mozilla Firefox Crash Reporting Component
CVE-2026-92047 is a privilege escalation vulnerability (CWE-269, improper privilege management) in the Crash Reporting component of Mozilla Firefox, rated high severity at CVSS 3.1 8.8. The attack is network-reachable with low complexity but requires user interaction, meaning a victim must be tricked into triggering the vulnerable crash reporting flow, after which the attacker can escalate privileges with high impact on confidentiality, integrity, and availability. Successful exploitation could allow an attacker to gain elevated privileges on the affected system, potentially escaping the browser's normal security boundaries. All users of Firefox before version 156 and Firefox ESR before 153.3 are affected. Mozilla has fixed the flaw in Firefox 156 and Firefox ESR 153.3; no public proof of concept or in-the-wild exploitation is currently known.
What to do: Upgrade desktop Firefox to version 156 or later and Firefox ESR to 153.3 or later as soon as possible, prioritizing managed fleets where ESR rollouts can lag. Enterprise and IT admins should verify no legacy ESR branches remain deployed, since those would not receive this fix. While no exploitation has been observed, the high CVSS score and broad Firefox install base make prompt patching prudent.
| Mozilla Firefox | before 156 |
| Mozilla Firefox ESR | before 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.