Junglewise Threat Intelligence

CVE-2026-8952: Mozilla Firefox privilege escalation in Application Update component

CVE-2026-8952 · Severity: info · CVSS 6.1 · Published 2026-05-19

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security flaw was identified in the Firefox web browser's update mechanism. This vulnerability could allow a user or malicious program already on a computer to gain higher-level system permissions than they should normally have. This could potentially lead to unauthorized changes to the software or the operating system. The issue has been resolved in Firefox version 151.

Technical details

A privilege escalation vulnerability exists in the Application Update component of Mozilla Firefox. While specific technical details are restricted in the associated bug report, the flaw allows an attacker with local access to elevate their privileges by exploiting the update process. This typically involves manipulating the service or files used by the browser to apply software updates. The vulnerability was addressed in Firefox 151 by improving the security controls within the update mechanism. Mozilla rated this as a 'moderate' impact issue.

Affected products

  • Mozilla Firefox < 151

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats