CVE-2026-84117

8.8

Mozilla · Firefox

A privilege escalation vulnerability exists in Firefox for Android that allows an attacker to gain unauthorized elevated permissions.

Executive summary

Mozilla Firefox for Android contains a privilege escalation vulnerability that could allow an attacker to achieve full control over the application environment.

Vulnerability

This is a privilege escalation flaw affecting the Android version of Firefox. The vulnerability allows an unauthenticated attacker to bypass standard application restrictions and gain elevated privileges.

Business impact

The potential for privilege escalation poses a significant risk to the integrity and confidentiality of user data stored within the browser. Given the CVSS score of 8.8, this vulnerability is classified as High severity and could lead to unauthorized access to sensitive information, session hijacking, or the execution of malicious actions within the context of the application.

Remediation

Immediate Action: All users must update Firefox for Android to version 155 or later immediately to apply the vendor-supplied fix.

Proactive Monitoring: Security teams should monitor for unusual application behavior or unauthorized permission changes on Android devices within the enterprise environment.

Compensating Controls: Ensure that mobile device management policies restrict the installation of unauthorized applications and enforce secure configuration profiles to limit the impact of potential browser-based exploits.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available in the provided data.

Analyst recommendation

The vulnerability represents a critical risk to mobile device security, specifically regarding the browser's ability to maintain privilege boundaries. Organizations should prioritize the deployment of the update to version 155 to remediate the flaw and prevent potential exploitation, as privilege escalation vulnerabilities are frequent targets for malicious actors seeking persistent access to user devices.

More Mozilla CVEs

Sources

Originally found and disclosed by HiWorld, per the CVE Program record.