Executive brief
Firefox for Android is a web browser used to access websites on mobile devices. This vulnerability allows an attacker to escalate privileges on an Android device, potentially gaining unauthorized access to sensitive data or system functions. The issue has been patched in Firefox 156.
Technical details
CVE-2026-92033 is a privilege escalation vulnerability affecting Firefox for Android. The specific technical root cause is not fully detailed in the advisory, but the vulnerability allows an attacker to execute code with elevated privileges. The vulnerability was addressed by Mozilla in Firefox 156. Exploitation requires local or adjacent access to a device running an affected version of Firefox for Android.
Affected products
- Mozilla Firefox before 156
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Firefox 156