Description
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The flaw in Firefox for Android permits an attacker to gain elevated privileges on the device. By exploiting a weakness in the privilege management subsystem, a malicious actor can, in theory, elevate authority from a normal application user to a higher privileged level, potentially accessing sensitive data or performing unauthorized actions. This vulnerability is classified as CWE-269, reflecting improper handling of privilege escalation.

Affected Systems

Devices running Firefox for Android versions older than 156 are affected. The issue was identified and addressed in update 156; therefore any installation of Firefox on Android prior to that revision is at risk. The affected product is Mozilla's Firefox browser for the Android operating system.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is < 1%, and it is not listed in CISA’s KEV catalog, implying no confirmed widespread exploitation yet. The attack vector is not explicitly detailed in the advisory; the likely vector is through malicious web content or potentially untrusted extensions, given the nature of a privilege escalation. Because of the high severity, it is advisable to act promptly to mitigate potential exploitation.

Generated by OpenCVE AI on September 17, 2026 at 16:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox for Android to version 156 or newer from the official Mozilla channel or Google Play store.
  • As a temporary safeguard, avoid using the browser when browsing untrusted sites or disable extensions until a patch is available.
  • Stay informed by reviewing Mozilla security advisories and apply any subsequent patches promptly.

Generated by OpenCVE AI on September 17, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Mobile
CPEs cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:android:*:*
Vendors & Products Mozilla firefox Mobile

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
Title Privilege escalation in Firefox for Android
References

Subscriptions

Mozilla Firefox Firefox Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-16T03:55:51.465Z

Reserved: 2026-09-15T12:33:53.450Z

Link: CVE-2026-92033

cve-icon Vulnrichment

Updated: 2026-09-15T13:32:30.938Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:16:54.623

Modified: 2026-10-05T18:02:06.027

Link: CVE-2026-92033

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T12:33:53Z

Links: CVE-2026-92033 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management