Junglewise Threat Intelligence

CVE-2026-92017: Mozilla Firefox privilege escalation in DOM Service Workers

CVE-2026-92017 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox's DOM Service Workers component contains a privilege escalation vulnerability that allows an attacker to execute code with elevated privileges. This could enable unauthorized access to browser capabilities and user data. The vulnerability affects multiple Firefox and Thunderbird versions and has been patched in recent security releases.

Technical details

This is a privilege escalation vulnerability in the DOM: Service Workers component of Firefox. Service Workers are background scripts that handle offline functionality and background tasks in web applications. The vulnerability allows an attacker to escalate privileges beyond the intended scope of Service Worker execution, potentially gaining access to protected browser APIs or data. The attack requires network access and likely interaction with a malicious website. Mozilla has patched the issue in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, and corresponding Thunderbird versions.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR 115 before 115.41, 140 before 140.16, 153 before 153.3
  • Mozilla Thunderbird 140 before 140.16, 153 before 153.3, before 156

Timeline

  • 2026-09-15: disclosed: Published in Mozilla Foundation Security Advisory 2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, 140.16, 153.3, and corresponding Thunderbird versions

References

Related threats