Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-84117 is a privilege escalation vulnerability affecting Firefox for Android that allows attackers to gain elevated system permissions beyond their intended access level. This flaw is particularly concerning because mobile browsers often handle sensitive operations like authentication, payment processing, and access to device resources. Android users running Firefox versions prior to 155 are directly affected, making this a widespread threat across the mobile ecosystem where Firefox maintains a significant user base. The high CVSS score of 8.8 reflects the severity of allowing unprivileged processes to escalate their capabilities on a device.
While this CVE currently maps to CWE-284 (Improper Access Control) rather than specific MITRE ATT&CK techniques, Casky's 754 security skills—powered by Claude AI's extended reasoning—would detect the attack patterns associated with privilege escalation behaviors. Practitioners using Casky would identify reconnaissance activities (T1592: Gather Victim Host Information), exploitation attempts targeting the Firefox process boundary, and post-exploitation indicators like unexpected system permission requests or process spawning patterns. The platform's skill set enables detection of lateral movement attempts and credential access that typically follow successful privilege escalation, helping security teams correlate Firefox Android exploitation with broader attack chains even in the absence of formally mapped MITRE techniques.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-84117. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation