ZeroHour

CVE-2026-92047

mass

Privilege Escalation in Mozilla Firefox Crash Reporting Component

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92047 is a privilege escalation vulnerability (CWE-269, improper privilege management) in the Crash Reporting component of Mozilla Firefox, rated high severity at CVSS 3.1 8.8. The attack is network-reachable with low complexity but requires user interaction, meaning a victim must be tricked into triggering the vulnerable crash reporting flow, after which the attacker can escalate privileges with high impact on confidentiality, integrity, and availability. Successful exploitation could allow an attacker to gain elevated privileges on the affected system, potentially escaping the browser's normal security boundaries. All users of Firefox before version 156 and Firefox ESR before 153.3 are affected. Mozilla has fixed the flaw in Firefox 156 and Firefox ESR 153.3; no public proof of concept or in-the-wild exploitation is currently known.

What to do: Upgrade desktop Firefox to version 156 or later and Firefox ESR to 153.3 or later as soon as possible, prioritizing managed fleets where ESR rollouts can lag. Enterprise and IT admins should verify no legacy ESR branches remain deployed, since those would not receive this fix. While no exploitation has been observed, the high CVSS score and broad Firefox install base make prompt patching prudent.

Affected
Mozilla Firefoxbefore 156
Mozilla Firefox ESRbefore 153.3
Estimated exposure
mass≈100M+ users (Firefox desktop has roughly 150-200 million active users worldwide) — Firefox's global desktop browser usage (roughly 2-3% of internet users) plus widespread enterprise ESR deployments puts the affected population well above the 1M-user threshold, though the exact number of unpatched installations is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.