Executive brief
A vulnerability in the messaging system of Firefox and Thunderbird could allow a malicious website to gain elevated privileges on a user's computer. If exploited, an attacker who has already compromised a browser process could bypass security prompts to install malicious browser extensions or hijack the user's homepage. This could lead to full control over the browser, theft of sensitive data, or persistent monitoring of user activity.
Technical details
A privilege escalation vulnerability exists in the Messaging System component of Mozilla browsers due to missing 'remoteTypes' restrictions on the 'AboutMessagePreviewParent' JSWindowActor. This omission allows a compromised content process to communicate with the parent process and invoke 'SpecialMessageActions.handleAction()' without proper authorization. An attacker can exploit this to trigger privileged actions such as 'INSTALL_ADDON_FROM_URL' (which uses SystemPrincipal to bypass site-level installation prompts) or 'SET_PREF' to modify browser settings like the homepage. The attack involves spoofing the document URI to 'about:messagepreview' via 'RecvUpdateDocumentURI' to bypass parent-side match checks. Patches are available in Firefox 148, Firefox ESR 115.33, and Firefox ESR 140.8.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 115.33, < 140.8
- Mozilla Thunderbird < 148, < 140.8
- Red Hat Red Hat Enterprise Linux Server 7 ELS affected
Timeline
- 2026-02-24: advisory: Mozilla Foundation Security Advisory 2026-13 published.
- 2026-02-24: patched: Fixed in Firefox 148 and ESR releases.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2015305
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338