Impact
The flaw in Firefox for Android permits an attacker to gain elevated privileges on the device. By exploiting a weakness in the privilege management subsystem, a malicious actor can, in theory, elevate authority from a normal application user to a higher privileged level, potentially accessing sensitive data or performing unauthorized actions. This vulnerability is classified as CWE-269, reflecting improper handling of privilege escalation.
Affected Systems
Devices running Firefox for Android versions older than 156 are affected. The issue was identified and addressed in update 156; therefore any installation of Firefox on Android prior to that revision is at risk. The affected product is Mozilla's Firefox browser for the Android operating system.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is < 1%, and it is not listed in CISA’s KEV catalog, implying no confirmed widespread exploitation yet. The attack vector is not explicitly detailed in the advisory; the likely vector is through malicious web content or potentially untrusted extensions, given the nature of a privilege escalation. Because of the high severity, it is advisable to act promptly to mitigate potential exploitation.
OpenCVE Enrichment