ZeroHour

CVE-2026-92054

mass

Memory Corruption Privilege Escalation in Mozilla Firefox and Firefox ESR

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92054 is a privilege escalation vulnerability in the Memory component of Mozilla Firefox, classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer), indicating a memory corruption flaw. Exploitation requires user interaction over the network, meaning a victim typically must visit attacker-controlled or compromised web content for the bug to trigger. A successful exploit gives the attacker high impact on confidentiality, integrity, and availability — consistent with escaping normal browser content-process restrictions and running code with elevated privileges inside the browser. The flaw affects Mozilla Firefox versions prior to 156 and Firefox ESR versions prior to 153.3, which are the releases containing the fix. There is no known public proof of concept and the issue is not on the CISA Known Exploited Vulnerabilities catalog, so no in-the-wild exploitation has been reported to date.

What to do: Update all Firefox desktop installations to Firefox 156 and all Firefox ESR deployments to Firefox ESR 153.3 as soon as possible; enterprises should verify their ESR channel and push the patched build via their management tools. Users can confirm their version via the browser's Help > About dialog and enable automatic updates. Monitor Mozilla's security advisories for any follow-up details on this issue.

Affected
Mozilla Firefoxversions prior to 156 (fixed in Firefox 156)
Mozilla Firefox ESRversions prior to 153.3 (fixed in Firefox ESR 153.3)
Estimated exposure
mass≈150–200 million users potentially exposed (unpatched Firefox desktop installations worldwide, plus enterprise Firefox ESR deployments) — Firefox maintains roughly 2–3% of the global desktop browser market with a user base commonly estimated in the 150–200 million range, and Firefox ESR is widely deployed in managed enterprise environments; any installations not yet updated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.