Description
Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A buffer overrun in the Memory component (CWE‑119) allows an attacker who can supply corrupt data to corrupt the process’s memory. The corruption can be used to elevate privileges within the browser or mail client or to execute arbitrary code, potentially leading to full system compromise.

Affected Systems

All Mozilla Firefox releases prior to version 156, and the Firefox ESR release before 153.3, as well as all versions of Thunderbird earlier than 156 are vulnerable. The vulnerability was resolved in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. While the description does not specify the attack surface, the nature of the memory corruption suggests it can be triggered by malicious input to the component, which may be delivered remotely (e.g., through a crafted web page or email) or locally by executing untrusted code. The likely attack vector is therefore either remote or local, depending on how the vulnerable input can be reached. The risk is elevated because the fault permits privilege escalation and potential arbitrary code execution.

Generated by OpenCVE AI on September 20, 2026 at 17:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to 156 or newer, or to Firefox ESR 153.3 or newer, and upgrade Mozilla Thunderbird to 156 or newer; this applies the Memory component patch.
  • If an upgrade is not immediately possible, run the affected applications with the minimum user permissions required and avoid running them as an administrator or root.
  • Continuously review system logs for abnormal memory usage, crashes, or repeated failed allocations that could signal an attempted exploitation.

Generated by OpenCVE AI on September 20, 2026 at 17:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:15:00 +0000


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Privilege escalation in the Memory component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-16T14:24:40.662Z

Reserved: 2026-09-15T12:34:15.099Z

Link: CVE-2026-92054

cve-icon Vulnrichment

Updated: 2026-09-15T13:10:03.517Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T13:16:58.800

Modified: 2026-09-16T19:34:05.910

Link: CVE-2026-92054

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T12:34:15Z

Links: CVE-2026-92054 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:15:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-825

    Expired Pointer Dereference