Executive brief
Firefox's developer tools component contains a privilege escalation vulnerability that allows a malicious actor to gain elevated access to browser functionality. This could lead to unauthorized control over sensitive browser operations and user data. The issue affects multiple Mozilla products and has been patched in recent versions.
Technical details
A privilege escalation vulnerability exists in the DevTools component of Mozilla Firefox and Thunderbird. The vulnerability allows an attacker with network access to elevate their privileges within the browser sandbox. The exact attack vector and preconditions are not fully detailed in the available advisory content, but the high CVSS score (8.8) indicates significant impact on confidentiality, integrity, and availability. Patches are available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird ESR before 153.3
Timeline
- 2026-09-15: disclosed: Vulnerability disclosed and fixed versions released
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3