CVE-2026-4722Privilege Context Switching Error in Mozilla Firefox

Severity
8.8HIGHNVD
EPSS
0.0%
top 96.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 24

Description

Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDmozilla/firefox< 149.0

🔴Vulnerability Details

3
GHSA
GHSA-fmr6-7878-wx6p: Privilege escalation in the IPC component2026-03-24
OSV
CVE-2026-4722: Privilege escalation in the IPC component2026-03-24
CVEList
Privilege escalation in the IPC component2026-03-24

📋Vendor Advisories

4
Red Hat
firefox: Privilege escalation in the IPC component2026-03-24
Debian
CVE-2026-4722: firefox - Privilege escalation in the IPC component. This vulnerability affects Firefox < ...2026
Mozilla
Mozilla Foundation Security Advisory 2026-23: CVE-2026-4722
Mozilla
Mozilla Foundation Security Advisory 2026-20: CVE-2026-4722

🕵️Threat Intelligence

1
Wiz
CVE-2026-4722 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-4722 — Privilege Context Switching Error | cvebase