Executive brief
Firefox and Thunderbird browsers contain a privilege escalation vulnerability in their WebExtensions component, which allows extensions to run additional code with elevated privileges. An attacker could exploit this through a malicious browser extension to gain unauthorized access to sensitive browser data and system resources, potentially compromising user privacy and security.
Technical details
This vulnerability is a privilege escalation flaw in the WebExtensions component (CVE-2026-92015) reported by Quy Pham. The exact root cause is not detailed in available public summaries, but privilege escalation in WebExtensions typically involves bypass of the extension sandbox or capability isolation mechanisms. The vulnerability affects Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR across multiple versions. It requires extension installation or interaction but can lead to full extension privilege escalation. Mozilla has patched the issue in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Firefox Before 156
- Mozilla Firefox ESR Before 115.41, 140.x before 140.16, 153.x before 153.3
- Mozilla Thunderbird Before 156
- Mozilla Thunderbird ESR Before 140.16, 153.x before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92015 published in MFSA2026-90
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, 140.16, 153.3, Thunderbird 156, 140.16, 153.3