CVE-2026-4722

8.8

Mozilla · Firefox, Thunderbird

A privilege escalation vulnerability exists in the Inter-Process Communication (IPC) component of Mozilla Firefox and Thunderbird, potentially allowing full system compromise.

Executive summary

A critical privilege escalation vulnerability in the IPC component of Mozilla Firefox and Thunderbird enables attackers to gain elevated system permissions.

Vulnerability

This is a privilege escalation flaw within the IPC component that can be triggered by an unauthenticated attacker, provided they can induce a user to interact with malicious content. The vulnerability leverages the browser's communication architecture to bypass standard security boundaries and execute arbitrary actions with higher privileges.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain unauthorized control over the affected application, leading to potential data exfiltration, unauthorized modification of user data, or arbitrary code execution. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to a total compromise of the host system. Such an event would result in significant operational disruption and severe reputational damage to the organization.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 149 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual process spawning activities or unexpected IPC communication patterns originating from browser-related services.

Compensating Controls: Deploy browser-based security policies that restrict cross-origin requests and employ endpoint detection and response tools to identify and block unauthorized privilege elevation attempts.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability necessitates an immediate organization-wide update to Mozilla Firefox and Thunderbird version 149. Administrators should prioritize deployment of these patches to all workstations and servers to mitigate the risk of remote code execution or privilege escalation. Failure to update leaves systems exposed to potential exploitation that could bypass standard security controls.

More Mozilla CVEs

Sources

Originally found and disclosed by Nika Layzell, per the CVE Program record.