Junglewise Threat Intelligence

CVE-2026-92043: Mozilla Firefox privilege escalation in Audio/Video component

CVE-2026-92043 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox is a widely-used web browser that processes audio and video content from websites. A flaw in how Firefox handles audio and video data could allow an attacker to gain elevated privileges on a user's system, potentially compromising the security and privacy of all data accessible to that user.

Technical details

This vulnerability is a privilege escalation caused by incorrect boundary conditions in the Audio/Video component of Firefox. The flaw allows an attacker to potentially escape normal process isolation boundaries and execute code with elevated privileges. The vulnerability is triggered when processing specially crafted audio or video content, likely through a malicious webpage or embedded media. Mozilla addressed this issue in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird ESR before 153.3

Timeline

  • 2026-09-15: disclosed: Vulnerability disclosed in Mozilla Security Advisory MFSA2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats