Junglewise Threat Intelligence

CVE-2026-92062: Mozilla Firefox privilege escalation in Session Restore component

CVE-2026-92062 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a privilege escalation vulnerability in the Session Restore component, which is used to restore user browsing sessions and tabs after a browser restart. An attacker exploiting this flaw could gain elevated privileges on a system, potentially allowing unauthorized access to sensitive data or system resources.

Technical details

This vulnerability is a privilege escalation flaw in the Session Restore component of Firefox and Thunderbird. The Session Restore feature handles the restoration of user sessions, including open tabs and browser state, across application restarts. The vulnerability likely stems from improper validation or sandbox enforcement when processing persisted session data. Exploitation requires local access to the affected system and would typically occur when the browser restores a malicious or tampered session state, allowing an attacker to execute code with elevated privileges. Patches are available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox below 156
  • Mozilla Firefox ESR below 153.3
  • Mozilla Thunderbird below 156
  • Mozilla Thunderbird below 153.3

Timeline

  • 2026-09-15: disclosed: Vulnerability published and fixes released
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats