Mozilla Firefox and Firefox ESR Privilege Escalation Vulnerability in the DOM: Notifications Component

Vulnerability

A privilege escalation vulnerability has been identified in the DOM: Notifications component of Mozilla Firefox. This issue affects Firefox versions prior to 146, as well as Firefox ESR versions prior to 115.31 and prior to 140.6. The vulnerability allows for unauthorized elevation of privileges, which could potentially be exploited to gain elevated rights or access within the application.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to gain elevated rights or access within the application.

Remediation

Users can upgrade to Firefox 146 or Firefox ESR 115.31 or 140.6 to address this vulnerability.

Added: Dec 9, 2025, 8:40 PM
Updated: Dec 9, 2025, 8:40 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
4.7
remediation
7.7
relevance
1.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.