PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92033 Mozilla CVE debrief

A privilege escalation vulnerability exists in Firefox for Android, which was fixed in Firefox 156. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. This vulnerability affects Android Firefox installations, allowing attackers to potentially gain elevated privileges. Defenders should review and verify their installations to ensure they are updated to the latest version. The vulnerability was reported to Mozilla and fixed in Firefox 156, highlighting the importance of keeping software up-to-date.

Vendor
Mozilla
Product
Firefox
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-10-05
Advisory published
2026-09-15
Advisory updated
2026-10-05

Who should care

Defenders responsible for managing and securing Android Firefox installations should be aware of this vulnerability and take steps to verify and update their installations.

Why it matters

A privilege escalation vulnerability in Firefox for Android requires defenders to verify and update installations to prevent potential exploitation.

  • Defenders should verify Android Firefox installations to prevent potential privilege escalation attacks.
  • Security teams should review and update incident response plans to address potential exploitation attempts.

Technical summary

A privilege escalation vulnerability exists in Firefox for Android, which can be exploited by an attacker to gain elevated privileges. The vulnerability was fixed in Firefox 156 and affects Android Firefox installations. This vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Defenders should prioritize verifying Android Firefox installations and ensuring they are updated to version 156 or later.

Defensive priority

Defenders should prioritize verifying Android Firefox installations and ensuring they are updated to version 156 or later.

Recommended defensive actions

  • Verify Android Firefox installations and ensure they are updated to version 156 or later.
  • Monitor Firefox for Android installations for potential exploitation attempts.
  • Review and update incident response plans to address potential privilege escalation attacks.

Evidence notes

The vulnerability was reported to Mozilla and fixed in Firefox 156. The NVD entry is currently Analyzed. The CVE record was published on 2026-09-15T13:16:54.623Z and has not been modified since then. Evidence of exploitation attempts may be found in relevant monitoring and detection logs. Defenders should verify Android Firefox installations and ensure they are updated to version 156 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92033 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92033

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92033 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92033

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.