Executive brief
Mozilla Firefox was found to have a privilege escalation vulnerability within its web worker component, which handles background scripts. An attacker could potentially exploit this to gain higher levels of access or permissions than intended within the browser environment. This issue has been resolved in Firefox version 153.
Technical details
A privilege escalation vulnerability exists in the DOM: Workers component of Mozilla Firefox. While specific root cause details are restricted in the associated Bugzilla report, the vulnerability allows for an escalation of privilege within the browser's Document Object Model (DOM) execution environment. The attack vector typically involves a malicious website leveraging Web Workers to bypass security boundaries. This issue is fixed in Firefox 153.
Affected products
- Mozilla Firefox < 153
Timeline
- 2026-07-21: advisory
- 2026-07-21: disclosed
- 2026-07-21: patched