Executive brief
Firefox for Android contains a privilege escalation vulnerability that could allow an attacker to gain elevated permissions within the browser or access sensitive browser functionality. This vulnerability affects mobile users and was resolved in Firefox 155.
Technical details
This is a privilege escalation vulnerability specific to Firefox for Android. While the advisory does not provide detailed technical information about the vulnerability mechanism, the high CVSS score of 8.8 and classification as a privilege escalation suggest a significant elevation of privileges within the browser sandbox or operating system context. The vulnerability was identified internally by Mozilla security researchers and patched in Firefox 155 released on September 1, 2026. No evidence of active exploitation in the wild has been reported at the time of disclosure.
Affected products
- Mozilla Firefox prior to 155
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in Firefox 155