ZeroHour

CVE-2026-92062

mass

Privilege Escalation via Session Restore in Mozilla Firefox

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92062 is a privilege escalation vulnerability (CWE-269, improper privilege management) in the Session Restore component of Mozilla Firefox. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R) indicates a network-based attack that requires user interaction, meaning a victim likely needs to visit attacker-controlled content or open a maliciously crafted session for the flaw to trigger. A successful exploit lets the attacker escape intended permission boundaries and gain elevated privileges within the browser context, with high impact on confidentiality, integrity, and availability. All users of Firefox releases prior to Firefox 156 and Firefox ESR releases prior to 153.3 are affected. No public proof of concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation.

What to do: Upgrade to Firefox 156 or later, or Firefox ESR 153.3 or later, immediately. Enterprise and managed deployments pinned to older ESR builds should accelerate rollout of 153.3 and verify update policies (e.g., enterprise group policy or MDM-managed update rings) are not blocking the patched release. Because exploitation requires user interaction, defenders should also reinforce caution with unsolicited links and unexpected session-restore prompts, and audit for users who have disabled automatic updates.

Affected
Mozilla Firefoxversions prior to Firefox 156
Mozilla Firefox ESR (Extended Support Release)versions prior to Firefox ESR 153.3
Estimated exposure
massplausibly tens of millions of users on pre-156 Firefox / pre-153.3 ESR at any given time, out of Firefox's ≈150M+ global user base — Firefox has an estimated 150M+ users worldwide, and even with auto-updates enabled, a meaningful lagging fraction typically runs pre-fix release or ESR versions after a patch ships.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.