Junglewise Threat Intelligence

CVE-2026-92054: Mozilla Firefox privilege escalation in Memory component

CVE-2026-92054 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a memory safety vulnerability that allows attackers to escalate their privileges on the affected system. This vulnerability affects multiple versions of both applications and requires immediate patching to protect users from potential system compromise and unauthorized access.

Technical details

A privilege escalation vulnerability exists in the Memory component of Firefox and Thunderbird due to memory safety issues. The vulnerability allows an attacker to escape the browser sandbox and achieve elevated privileges on the host system. The attack vector is network-based, requiring no user interaction beyond normal browsing. The vulnerability was addressed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird ESR before 153.3

Timeline

  • 2026-09-15: disclosed: Vulnerability announced by Mozilla Foundation
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3

References

Related threats