Sceawere

Vulnerability Detail

CVE-2026-100824UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Firefox Places Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
12h ago
Vendor
Mozilla
Product
Firefox
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-29T13:17:47.700Z",
  "pubdate": "2026-09-29T13:17:47.700Z",
  "executiveSummary": "This vulnerability involves a privilege escalation flaw located within the Places component of the Firefox browser. The Places subsystem, which manages browser history, bookmarks, and associated metadata, fails to adequately enforce security boundaries, potentially allowing an attacker to execute operations with escalated privileges.\nThe vulnerability affects Firefox ESR 153.4 and Firefox 157. Successful exploitation may enable an attacker to perform unauthorized actions within the browser context, effectively bypassing intended access control restrictions. The risk implications are significant, as this could lead to the compromise of user data or the execution of malicious scripts with elevated system-level authority.\nExploitation generally requires a sophisticated adversary capable of interacting with the Places database or exploiting internal API calls. The primary impact involves a breach of the browser’s security model, granting the attacker functionality beyond their permitted scope. There is no indication of remote authentication requirements, but the exploit is contingent upon the attacker being able to trigger the vulnerable code path within the Places component.\nOrganizations and individual users are strongly advised to update to the latest versions of Firefox and Firefox ESR to neutralize the security risk posed by this privilege escalation flaw.",
  "technicalDetails": "The root cause of this vulnerability lies in an insufficient validation of internal requests processed by the Places component, which is responsible for the management of the browser's SQLite-backed storage for history and bookmarks. Specifically, the component fails to properly verify the context or origin of specific operations, allowing for the injection or manipulation of commands that transcend the security domain assigned to the process initiating the request.\nThe Places component acts as a high-privilege service that interacts directly with sensitive browser databases. In this vulnerability, the internal API architecture lacks the necessary sandboxing or 'origin-check' mechanisms to distinguish between legitimate user-initiated requests and malicious requests masquerading as authorized browser operations. Consequently, an attacker can leverage this oversight to escalate privileges from a restricted sandbox or a low-privilege script environment to the browser’s chrome-privileged scope.\nThe attack flow typically proceeds through the following phases: First, the attacker identifies a mechanism to invoke specific internal functions exposed by the Places component. This is often achieved through the manipulation of browser-specific protocols or via vulnerable script execution contexts that retain access to privileged interfaces. Second, the attacker crafts a payload designed to exploit the lack of rigorous input sanitization or origin validation within these internal interfaces. Third, upon execution, the Places component processes the request under its own elevated security context rather than the caller's context, effectively ignoring the expected security boundaries.\nOnce the initial privilege escalation is achieved, the attacker can execute arbitrary database queries against the places.sqlite file. This grants the attacker the ability to modify or exfiltrate sensitive data, including browser history, saved bookmarks, and potentially session-specific metadata. Furthermore, because the Places component is tightly integrated with the browser’s core functionality, this escalation may serve as a secondary vector to facilitate further exploitation, such as cross-origin request forgery or the injection of malicious content into seemingly trusted user interfaces. The vulnerability affects Firefox ESR 153.4 and Firefox 157, necessitating a code-level fix that enforces strict origin-validation and interface-locking for all Places component interactions."
}
CVE-2026-100824: Firefox Places Privilege Escalation (HIGH Severity, CVSS: 8.8) | Sceawere