CVE-2026-92054
massMemory Corruption Privilege Escalation in Mozilla Firefox and Firefox ESR
CVE-2026-92054 is a privilege escalation vulnerability in the Memory component of Mozilla Firefox, classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer), indicating a memory corruption flaw. Exploitation requires user interaction over the network, meaning a victim typically must visit attacker-controlled or compromised web content for the bug to trigger. A successful exploit gives the attacker high impact on confidentiality, integrity, and availability — consistent with escaping normal browser content-process restrictions and running code with elevated privileges inside the browser. The flaw affects Mozilla Firefox versions prior to 156 and Firefox ESR versions prior to 153.3, which are the releases containing the fix. There is no known public proof of concept and the issue is not on the CISA Known Exploited Vulnerabilities catalog, so no in-the-wild exploitation has been reported to date.
What to do: Update all Firefox desktop installations to Firefox 156 and all Firefox ESR deployments to Firefox ESR 153.3 as soon as possible; enterprises should verify their ESR channel and push the patched build via their management tools. Users can confirm their version via the browser's Help > About dialog and enable automatic updates. Monitor Mozilla's security advisories for any follow-up details on this issue.
| Mozilla Firefox | versions prior to 156 (fixed in Firefox 156) |
| Mozilla Firefox ESR | versions prior to 153.3 (fixed in Firefox ESR 153.3) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.