Executive brief
A vulnerability in Mozilla Firefox's WebExtensions component could allow a malicious browser extension to gain higher-level permissions than intended. Firefox is a widely used web browser, and WebExtensions are the standard system for browser add-ons. If exploited, this flaw could allow an attacker to bypass security restrictions, potentially leading to unauthorized access to user data or browser functionality.
Technical details
A privilege escalation vulnerability exists in the WebExtensions component of Mozilla Firefox. The flaw allows a crafted WebExtension to elevate its privileges beyond its defined manifest permissions. While specific root cause details are restricted in the associated Bugzilla report (Bug 2047240), the impact is categorized as moderate severity. An attacker would need to convince a user to install a malicious extension or compromise an existing one to exploit this vulnerability. The issue is resolved in Firefox 153 and Firefox ESR 140.13.
Affected products
- Mozilla Firefox < 153
- Mozilla Firefox ESR < 140.13
Timeline
- 2026-07-21: advisory: Mozilla Foundation Security Advisory 2026-68 and 2026-70 released.
- 2026-07-21: patched: Fixed in Firefox 153 and Firefox ESR 140.13.