Description
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
Published: 2026-09-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to increase privileges within Firefox for Android, potentially leading to the execution of code or access to sensitive data that was not intended for the user. The impact is limited to the scope of the application, but because it is a privilege escalation flaw, an attacker could gain elevated rights that might affect the broader device if additional exploitation is possible. The description does not specify exact mechanisms or conditions, so the full extent of the impact remains uncertain beyond the elevation of rights within the browser environment.

Affected Systems

Mozilla Firefox for Android versions prior to 155 are affected. All Android devices running an impacted Firefox installation are at risk if the browser is not updated to the patched release.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable, so an exact numeric risk estimate cannot be given. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of the flaw—privilege escalation—and the lack of disclosed constraints, it is inferred that exploitation may require the user to interact with a crafted web page or content within the browser. The attack vector is likely local or remote through the web content channel, but the specific conditions for successful exploitation are not detailed in the available information.

Generated by OpenCVE AI on September 1, 2026 at 13:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox to version 155 or newer on all affected Android devices.
  • If immediate update is not feasible, consider uninstalling or disabling the browser until a patched version is available.
  • Follow general Android security best practices: avoid installing or trusting unverified applications, keep the operating system and all apps up to date, and monitor for suspicious browser activity.

Generated by OpenCVE AI on September 1, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-272

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
Title Privilege escalation in Firefox for Android
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T13:43:43.672Z

Reserved: 2026-09-01T07:25:01.149Z

Link: CVE-2026-84117

cve-icon Vulnrichment

Updated: 2026-09-01T13:43:37.340Z

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:05.487

Modified: 2026-09-01T14:17:48.100

Link: CVE-2026-84117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:14:59Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-272

    Least Privilege Violation

  • CWE-284

    Improper Access Control