Description
Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
In plain language
AI Act nowA malicious browser or email extension can take over Firefox or Thunderbird after a user interacts with a crafted website, so small businesses should update affected installations now.
Privilege escalation in the WebExtensions component lets crafted web content cause a malicious extension to receive excessive permissions and fully compromise the client application.
What to do now
- Check whether your staff use Firefox or Thunderbird and record each installed version.
- Update Firefox to 115.41, 140.16, 153.3, or 156, as appropriate for your release branch.
- Update Thunderbird to 140.16, 153.3, or 156, as appropriate for your release branch.
- Remove unneeded extensions and investigate any extension installed outside your normal approval process.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-92015 and every CVE in our database. Create a free account — no credit card required.
Create Free Account