ZeroHour

CVE-2026-92073

mass

Firefox Enterprise Policies Privilege Escalation (Fixed in Firefox 156 & ESR 153.3)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92073 is a privilege escalation vulnerability (CWE-269, improper privilege management) in the Enterprise Policies component of Mozilla Firefox. Based on the CVSS vector (network attack vector, no privileges required, user interaction required), exploitation likely involves convincing a target user to interact with attacker-controlled content, which then abuses the policies component to run with elevated privileges. A successful attacker gains high impact on confidentiality, integrity, and availability of the browser context and potentially the underlying system. All users running Firefox versions prior to Firefox 156 and Firefox ESR versions prior to 153.3 are affected, with enterprise-managed deployments that rely on policy configuration being particularly relevant. No public proof-of-concept is known, the flaw is not on the CISA KEV catalog, and no exploitation in the wild has been reported.

What to do: Update all Firefox installations to Firefox 156 or Firefox ESR 153.3 immediately, prioritizing enterprise-managed machines that use policies. or Group Policy configuration. Administrators should audit existing policy files and browser configurations for unexpected or unauthorized changes that could indicate tampering. Monitor Mozilla security advisories for follow-up details, since no public PoC exists but disclosure specifics may evolve.

Affected
Mozilla FirefoxAll versions prior to Firefox 156
Mozilla Firefox ESR (Extended Support Release)All versions prior to Firefox ESR 153.3
Estimated exposure
massOrder of 100-200 million users (Firefox's global desktop user base), subset of unpatched and enterprise-managed installs — Firefox maintains a global desktop user base commonly estimated at 150-250 million, so even a fraction running unpatched builds represents tens of millions of potentially affected systems; the number of installs actually exposing the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.