Junglewise Threat Intelligence

CVE-2026-8972: Mozilla Firefox privilege escalation in WebRTC Audio/Video component

CVE-2026-8972 · Severity: info · CVSS 3.3 · Published 2026-05-19

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability in the Firefox web browser's WebRTC component could allow for unauthorized privilege escalation. WebRTC is the technology used for real-time communication like video calls and audio streaming within the browser. If exploited, this could allow a malicious website to gain higher levels of access than intended, potentially compromising user privacy or browser security settings.

Technical details

A privilege escalation vulnerability exists in the WebRTC: Audio/Video component of Mozilla Firefox. The flaw resides in how the browser handles real-time communication protocols, potentially allowing a malicious actor to bypass security boundaries. While specific technical root causes (such as specific API misuse or logic errors) are restricted in the associated Bugzilla report, the impact is categorized as privilege escalation. The vulnerability is reachable via network-delivered content (e.g., a malicious website) and requires user interaction (visiting the site). Mozilla has released Firefox 151 to remediate this issue.

Affected products

  • Mozilla Firefox < 151

Timeline

  • 2026-05-19: advisory: Mozilla Foundation Security Advisory 2026-46 published
  • 2026-05-19: patched: Fixed in Firefox 151

References

Related threats