Junglewise Threat Intelligence

CVE-2026-92015: Mozilla Firefox privilege escalation in WebExtensions

CVE-2026-92015 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird browsers contain a privilege escalation vulnerability in their WebExtensions component, which allows extensions to run additional code with elevated privileges. An attacker could exploit this through a malicious browser extension to gain unauthorized access to sensitive browser data and system resources, potentially compromising user privacy and security.

Technical details

This vulnerability is a privilege escalation flaw in the WebExtensions component (CVE-2026-92015) reported by Quy Pham. The exact root cause is not detailed in available public summaries, but privilege escalation in WebExtensions typically involves bypass of the extension sandbox or capability isolation mechanisms. The vulnerability affects Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR across multiple versions. It requires extension installation or interaction but can lead to full extension privilege escalation. Mozilla has patched the issue in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox Before 156
  • Mozilla Firefox ESR Before 115.41, 140.x before 140.16, 153.x before 153.3
  • Mozilla Thunderbird Before 156
  • Mozilla Thunderbird ESR Before 140.16, 153.x before 153.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-92015 published in MFSA2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, 140.16, 153.3, Thunderbird 156, 140.16, 153.3

References

Related threats