VYPR
High severity8.8NVD Advisory· Published May 19, 2026· Updated May 20, 2026

CVE-2026-8955

CVE-2026-8955

Description

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A privilege escalation vulnerability in the DOM: Workers component of Mozilla Firefox and Thunderbird allows an attacker to gain elevated privileges.

Vulnerability

A privilege escalation vulnerability exists in the DOM: Workers component of Firefox and Thunderbird. This affects Firefox versions prior to 151, Firefox ESR versions prior to 140.11, Thunderbird versions prior to 151, and Thunderbird ESR versions prior to 140.11 [1][2][3][4]. The specific code path can be triggered when processing Worker scripts.

Exploitation

An attacker would need to convince a user to visit a malicious website or open a crafted email in a browser-like context (scripting must be enabled). In Thunderbird, scripting is disabled by default when reading mail, but the flaw is still a risk in browser or browser-like contexts [2][3]. The attacker can craft a Worker that exploits the privilege escalation vulnerability.

Impact

Successful exploitation allows the attacker to obtain elevated privileges, potentially leading to further compromise beyond the normal sandbox restrictions [1]. The attacker can execute arbitrary code with the privilege level of the browser process, which could lead to full system compromise.

Mitigation

The vulnerability is fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11 released on May 19, 2026 [1][2][3][4]. Users should update to these versions or later. No workaround is available; installation of the updated version is the only mitigation.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.