Junglewise Threat Intelligence

CVE-2026-8970: Mozilla Firefox privilege escalation in Security component

CVE-2026-8970 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a popular web browser used for accessing the internet. A vulnerability in its security component could allow an attacker to gain higher-level permissions than intended within the application. This could potentially lead to unauthorized access to browser data or the ability to bypass certain security restrictions.

Technical details

A privilege escalation vulnerability exists in the Security component of Mozilla Firefox. The flaw allows for an elevation of privilege within the browser's execution context. While specific root cause details are restricted in the associated bug report (Bug 2032174), the vulnerability is classified as having low impact by the vendor. The issue is resolved in Firefox version 151 and Firefox ESR version 140.11. Attackers would likely need to entice a user to visit a malicious website to trigger the vulnerability.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: patched
  • 2026-05-19: advisory

References

Related threats