Cyber Resilience

CVE-2026-4722

Mozilla Firefox ≤ 149.0

Published
24 March 2026
Modified
13 April 2026
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0031 24th percentile
Risk Priority 63 floored blend · peak EPSS

Summary

CVE-2026-4722 is a high-severity an unspecified weakness vulnerability in Mozilla Firefox. Its CVSS base score is 8.8 (High).

Operationally, ranked at the 24th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2026-4722 is a privilege escalation vulnerability in the IPC component of Mozilla Firefox and Thunderbird. It affects versions of these browsers prior to 149, where the issue was addressed. Published on 2026-03-24, the vulnerability carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE category NVD-CWE-noinfo.

The vulnerability can be exploited by remote attackers requiring low attack complexity and no privileges, though user interaction is necessary. Successful exploitation enables high-impact consequences on confidentiality, integrity, and availability within the unchanged scope, allowing privilege escalation in the affected browser processes.

Mozilla's security advisories MFSA 2026-20 and MFSA 2026-23 detail the fix implemented in Firefox 149 and Thunderbird 149. Additional technical information is available in Bugzilla entry 2010097.

EU & UK References

Vulnerability Data

Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-23604Same product: Mozilla Firefox
CVE-2023-25733Same product: Mozilla Firefox
CVE-2024-2606Same product: Mozilla Firefox
CVE-2026-4715Same product: Mozilla Firefox
CVE-2023-23600Same product: Mozilla Firefox
CVE-2026-8391Same product: Mozilla Firefox
CVE-2024-1554Same product: Mozilla Firefox
CVE-2026-24868Same product: Mozilla Firefox
CVE-2024-0745Same product: Mozilla Firefox
CVE-2025-13014Same product: Mozilla Firefox

Affected Assets

mozilla
firefox
≤ 149.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References