CVE-2026-92062
massPrivilege Escalation via Session Restore in Mozilla Firefox
CVE-2026-92062 is a privilege escalation vulnerability (CWE-269, improper privilege management) in the Session Restore component of Mozilla Firefox. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R) indicates a network-based attack that requires user interaction, meaning a victim likely needs to visit attacker-controlled content or open a maliciously crafted session for the flaw to trigger. A successful exploit lets the attacker escape intended permission boundaries and gain elevated privileges within the browser context, with high impact on confidentiality, integrity, and availability. All users of Firefox releases prior to Firefox 156 and Firefox ESR releases prior to 153.3 are affected. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation.
What to do: Upgrade to Firefox 156 or later, or Firefox ESR 153.3 or later, immediately. Enterprise and managed deployments pinned to older ESR builds should accelerate rollout of 153.3 and verify update policies (e.g., enterprise group policy or MDM-managed update rings) are not blocking the patched release. Because exploitation requires user interaction, defenders should also reinforce caution with unsolicited links and unexpected session-restore prompts, and audit for users who have disabled automatic updates.
| Mozilla Firefox | versions prior to Firefox 156 |
| Mozilla Firefox ESR (Extended Support Release) | versions prior to Firefox ESR 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.