Junglewise Threat Intelligence

CVE-2026-8955: Mozilla Firefox privilege escalation in DOM: Workers

CVE-2026-8955 · Severity: info · CVSS 6.5 · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A privilege escalation vulnerability was identified in the Mozilla Firefox web browser's background processing component. This flaw could allow a malicious website to gain higher-level permissions than intended, potentially leading to unauthorized access to browser data or system resources. Users should update to the latest versions of Firefox or Firefox ESR to mitigate this risk.

Technical details

A privilege escalation vulnerability exists in the DOM: Workers component of Mozilla Firefox. The flaw allows for a bypass of security restrictions, potentially enabling an attacker to execute actions with elevated privileges within the browser context. The vulnerability is triggered when a user visits a specially crafted webpage. Mozilla has addressed this issue in Firefox 151 and Firefox ESR 140.11. While specific root cause details are restricted in the associated Bugzilla report (Bug 2031064), the impact is categorized by Mozilla as 'moderate' severity.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory
  • 2026-05-19: patched

References

Related threats