ZeroHour

CVE-2026-92055

mass

Privilege Escalation in Firefox DevTools Component

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92055 is a privilege escalation flaw (CWE-269, improper privilege management) in the DevTools component of Mozilla Firefox, rated high severity with a CVSS 3.1 score of 8.8. The attack vector is network-based with low attack complexity and requires no prior privileges, but it does require user interaction, meaning it is plausibly triggered by persuading a target to interact with attacker-controlled content. If exploited, an attacker gains high impacts to confidentiality, integrity, and availability, effectively breaking out of the intended privilege boundary of the browser component. All users of Firefox versions prior to 156 and Firefox ESR versions prior to 153.3 are affected, with fixes shipped in Firefox 156 and Firefox ESR 153.3. No public proof-of-concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Update all Firefox installations to version 156 or later, and Firefox ESR deployments to 153.3 or later, as soon as possible. Ensure automatic updates are enabled for consumer installs, and verify that enterprise-managed ESR fleets have received the patched build. Check browser inventory for any stale or kiosk-style deployments pinned to older builds, since these often miss routine update cycles.

Affected
Mozilla Firefoxversions prior to 156 (fixed in Firefox 156)
Mozilla Firefox ESR (Extended Support Release)versions prior to 153.3 (fixed in Firefox ESR 153.3)
Estimated exposure
mass≈100M+ users (Firefox's global install base of roughly 150-250 million, minus the auto-updated share) — Firefox maintains roughly 2-3% of global browser market share across a desktop internet population in the billions, yielding a user base in the hundreds of millions, most of whom auto-update but all of whom were exposed prior to patch…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.