Mozilla Firefox Open source web browser
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Mozilla Firefox.
Recent Mozilla Firefox Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-74 | Security Vulnerabilities fixed in Firefox 154 mfsa2026-74 | August 18, 2026 |
| mfsa2026-75 | Security Vulnerabilities fixed in Firefox ESR 115.39 mfsa2026-75 | August 18, 2026 |
| mfsa2026-77 | Security Vulnerabilities fixed in Firefox ESR 153.1 mfsa2026-77 | August 18, 2026 |
| mfsa2026-76 | Security Vulnerabilities fixed in Firefox ESR 140.14 mfsa2026-76 | August 18, 2026 |
| mfsa2026-73 | Security Vulnerabilities fixed in Firefox for Android 153.0.3 mfsa2026-73 | August 4, 2026 |
| mfsa2026-69 | Security Vulnerabilities fixed in Firefox ESR 115.38 mfsa2026-69 | July 21, 2026 |
| mfsa2026-68 | Security Vulnerabilities fixed in Firefox 153 mfsa2026-68 | July 21, 2026 |
| mfsa2026-70 | Security Vulnerabilities fixed in Firefox ESR 140.13 mfsa2026-70 | July 21, 2026 |
| mfsa2026-67 | Security Vulnerabilities fixed in Firefox 152.0.6 mfsa2026-67 | July 14, 2026 |
| mfsa2026-66 | Security Vulnerabilities fixed in Firefox for iOS 152.4 mfsa2026-66 | July 13, 2026 |
Known Exploited Mozilla Firefox Vulnerabilities
The following Mozilla Firefox vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CVE-2024-9680 Exploit Probability: 23.2% |
October 15, 2024 |
| Mozilla Firefox Security Feature Bypass Vulnerability |
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 Exploit Probability: 71.4% |
May 25, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 Exploit Probability: 2.3% |
March 7, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 Exploit Probability: 13.8% |
March 7, 2022 |
| Mozilla Firefox Information Disclosure Vulnerability |
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 Exploit Probability: 6.7% |
March 3, 2022 |
The vulnerability CVE-2015-4495: Mozilla Firefox Security Feature Bypass Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited Mozilla Firefox vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
EOL Dates
Ensure that you are using a supported version of Mozilla Firefox. Here are some end of life, and end of support dates for Mozilla Firefox.
| Release | EOL Date | Status |
|---|---|---|
| 154 | - |
Active
|
| 153 | - |
Active
|
| 152 | July 21, 2026 |
EOL
Mozilla Firefox 152 became EOL in 2026. |
| 151 | June 16, 2026 |
EOL
Mozilla Firefox 151 became EOL in 2026. |
| 150 | May 18, 2026 |
EOL
Mozilla Firefox 150 became EOL in 2026. |
| 149 | April 21, 2026 |
EOL
Mozilla Firefox 149 became EOL in 2026. |
| 148 | March 24, 2026 |
EOL
Mozilla Firefox 148 became EOL in 2026. |
| 147 | February 24, 2026 |
EOL
Mozilla Firefox 147 became EOL in 2026. |
| 146 | January 13, 2026 |
EOL
Mozilla Firefox 146 became EOL in 2026. |
| 145 | December 9, 2025 |
EOL
Mozilla Firefox 145 became EOL in 2025. |
| 144 | November 11, 2025 |
EOL
Mozilla Firefox 144 became EOL in 2025. |
| 143 | October 14, 2025 |
EOL
Mozilla Firefox 143 became EOL in 2025. |
| 142 | September 16, 2025 |
EOL
Mozilla Firefox 142 became EOL in 2025. |
| 141 | August 19, 2025 |
EOL
Mozilla Firefox 141 became EOL in 2025. |
| 140 | September 29, 2026 |
EOL This Year
Mozilla Firefox 140 will become EOL this year, in September 2026. |
| 139 | June 24, 2025 |
EOL
Mozilla Firefox 139 became EOL in 2025. |
| 138 | May 27, 2025 |
EOL
Mozilla Firefox 138 became EOL in 2025. |
| 137 | April 29, 2025 |
EOL
Mozilla Firefox 137 became EOL in 2025. |
| 136 | April 1, 2025 |
EOL
Mozilla Firefox 136 became EOL in 2025. |
| 135 | March 4, 2025 |
EOL
Mozilla Firefox 135 became EOL in 2025. |
By the Year
In 2026 there have been 390 vulnerabilities in Mozilla Firefox with an average score of 7.8 out of ten. Last year, in 2025 Firefox had 189 security vulnerabilities published. That is, 201 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.25.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 390 | 7.79 |
| 2025 | 189 | 7.54 |
| 2024 | 190 | 7.15 |
| 2023 | 180 | 7.38 |
| 2022 | 159 | 7.44 |
| 2021 | 123 | 7.13 |
| 2020 | 148 | 7.27 |
| 2019 | 121 | 7.44 |
| 2018 | 312 | 7.82 |
It may take a day or so for new Firefox vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Firefox Security Vulnerabilities
Memory corruption bugs in Firefox 153
CVE-2026-74989
9.8 - Critical
- August 18, 2026
Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Buffer Overflow
Firefox ESR 153.0 Memory Corruption Vulnerability (fixed in 153.1)
CVE-2026-74988
9.8 - Critical
- August 18, 2026
Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Buffer Overflow
CSS Parsing Component Site Isolation Flaw Fixed in Firefox 154 & ESR 153.1
CVE-2026-74986
9.1 - Critical
- August 18, 2026
Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Information Disclosure
Firefox 154 ESR 153.1 Fixed PrivEsc in Enterprise Policies
CVE-2026-74985
9.8 - Critical
- August 18, 2026
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Improper Privilege Management
Race Condition in JS Engine, Firefox <154, fixed v154
CVE-2026-74984
6.8 - Medium
- August 18, 2026
Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Race Condition
DoS in Firefox Widget component before 154/ESR153.1
CVE-2026-74982
7.5 - High
- August 18, 2026
Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Resource Exhaustion
Site Isolation Vulnerability in Web Codecs (Firefox <154, Thunderbird <154)
CVE-2026-74981
8.1 - High
- August 18, 2026
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Clickjacking Vulnerability in Firefox Android Downloads Component
CVE-2026-74980
6.5 - Medium
- August 18, 2026
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
Clickjacking
Mitigation bypass in Addons Manager (Firefox 154, ESR 153.1, Thunderbird 154)
CVE-2026-74979
9.8 - Critical
- August 18, 2026
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Authorization
Clickjacking in Firefox/Thunderbird widget component before v154
CVE-2026-74978
8.1 - High
- August 18, 2026
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Clickjacking
Firefox & Thunderbird Graphics INT Overflow CVE-2026-74977 Fixed 154
CVE-2026-74977
7.5 - High
- August 18, 2026
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Integer Overflow or Wraparound
Firefox Android Downloads Spoofing Vulnerability
CVE-2026-74975
5.4 - Medium
- August 18, 2026
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
User Interface (UI) Misrepresentation of Critical Information
Site isolation flaw in Firefox Graphics before v154
CVE-2026-74970
5.4 - Medium
- August 18, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Site Isolation Flaw in WebRender of Firefox/Thunderbird (v<154)
CVE-2026-74968
5.4 - Medium
- August 18, 2026
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Origin Validation Error
Same-Origin Policy Bypass in Service Workers (Firefox <154, Thunderbird <154)
CVE-2026-74956
9.1 - Critical
- August 18, 2026
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Object Type Confusion
CVE-2026-74958: WebRTC Info Disclosure before Firefox+Thunderbird 154
CVE-2026-74958
7.5 - High
- August 18, 2026
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Clickjacking
Web Audio side-channel in Firefox 154, Thunderbird 154
CVE-2026-74961
9.1 - Critical
- August 18, 2026
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Side Channel Attack
Firefox 154: Information Disclosure in Form Autofill
CVE-2026-74966
7.5 - High
- August 18, 2026
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Privacy violation
Clickjacking in Firefox for Android
CVE-2026-74951
6.5 - Medium
- August 18, 2026
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
Clickjacking
Mozilla Firefox AppUpd PrivEsc via Application Update Vulnerability
CVE-2026-74952
8.8 - High
- August 18, 2026
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Improper Privilege Management
Firefox Storage Cache API Side-Channel Info Disclosure (fixed 154)
CVE-2026-74954
7.5 - High
- August 18, 2026
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Side Channel Attack
Privilege Escalation via Request Handling in Firefox 154 & Thunderbird 154
CVE-2026-74955
8.8 - High
- August 18, 2026
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Improper Privilege Management
Use-After-Free in Firefox JavaScript GC Pre-154
CVE-2026-74937
8.8 - High
- August 18, 2026
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Dangling pointer
Firefox JS GC mitigation bypass before v154
CVE-2026-74938
9.1 - Critical
- August 18, 2026
Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Protection Mechanism Failure
Firefox 154/Thunderbird 154 PrivEsc via Graphics Component Pointer
CVE-2026-74947
8.8 - High
- August 18, 2026
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Release of Invalid Pointer or Reference
Privilege Escalation in Downloads API (before Firefox 154, Thunderbird 154)
CVE-2026-74950
8.8 - High
- August 18, 2026
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Improper Privilege Management
Mozilla Remote Settings Client Sandbox Escape in Firefox & Thunderbird
CVE-2026-75874
10 - Critical
- August 18, 2026
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
Protection Mechanism Failure
Mitigation Bypass in Mozilla DLP (Fixed in Firefox v154 & Thunderbird v154)
CVE-2026-74983
8.1 - High
- August 18, 2026
Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Protection Mechanism Failure
Thunderbird ESR 140.13/153 Memory Corruption CVE-2026-74990 Fixed 154
CVE-2026-74990
9.8 - Critical
- August 18, 2026
Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Buffer Overflow
Thunderbird ESR 140.13/153.0 Memory Corruption (CVE-2026-74987)
CVE-2026-74987
9.8 - Critical
- August 18, 2026
Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Buffer Overflow
Mozilla Firefox & Thunderbird DOM Disclosure (Push Subscriptions) before 154
CVE-2026-74972
4.3 - Medium
- August 18, 2026
Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Information Disclosure
Race cond Use-After-Free in Firefox/Thunderbird Graphics Comp (before 154)
CVE-2026-74973
4.2 - Medium
- August 18, 2026
Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Race Condition
Same-origin policy bypass in ImageLib (Firefox <=154, Thunderbird <=154)
CVE-2026-74974
5.4 - Medium
- August 18, 2026
Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
Firefox 154 / ESR 140.14 JIT miscompilation in JavaScript Engine (JIT component)
CVE-2026-74976
6.5 - Medium
- August 18, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Object Type Confusion
CVE-2026-74967: Sameor Poli Bypass in Firefox AV Playback (pre-154)
CVE-2026-74967
5.4 - Medium
- August 18, 2026
Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
Use-after-free in Layout:TextFonts (Firefox/Thunderbird) fixed in 154, ESR115.39
CVE-2026-74969
8.8 - High
- August 18, 2026
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Dangling pointer
CVE-2026-74971: Info Disclosure in Firefox DOM UI Events before 154
CVE-2026-74971
4.3 - Medium
- August 18, 2026
Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Information Disclosure
Mozilla Firefox Shell Integration PrivEsc (before v154)
CVE-2026-74965
8.8 - High
- August 18, 2026
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Improper Privilege Management
Integer Overflow in Firefox Graphics Comp (pre 154/ESR 140.14)
CVE-2026-74964
9.8 - Critical
- August 18, 2026
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Integer Overflow or Wraparound
Firefox SOP Bypass via Cookies Before v154
CVE-2026-74963
5.4 - Medium
- August 18, 2026
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
Firefox Site Isolation Issue in Networking:Cookies Component (before 154)
CVE-2026-74962
8.1 - High
- August 18, 2026
Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
Site Isolation Vulnerability in WebExtensions (Fixed in FF 154/ESR 140.14)
CVE-2026-74960
8.1 - High
- August 18, 2026
Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Origin Validation Error
Mitigation bypass in Firefox Storage Cache API before 154
CVE-2026-74959
9.1 - Critical
- August 18, 2026
Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Protection Mechanism Failure
Mitigation Bypass in Mozilla Safe Browsing (Firefox<154, Thunderbird<154)
CVE-2026-74957
8.1 - High
- August 18, 2026
Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Protection Mechanism Failure
Firefox/Thunderbird PrivEsc via Cookies (before v154)
CVE-2026-74953
8.8 - High
- August 18, 2026
Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Improper Privilege Management
Priv-esc via UAF in Canvas2D (Firefox/Thunderbird <154)
CVE-2026-74949
8.8 - High
- August 18, 2026
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Dangling pointer
Firefox DOM UAF in Core & HTML before v154
CVE-2026-74944
9.8 - Critical
- August 18, 2026
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Dangling pointer
Firefox 154: CanvasWebGL PrivEsc due to boundary check flaw
CVE-2026-74946
8.8 - High
- August 18, 2026
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Buffer Overflow
Info Disclosure: Graphics Comp prior to FF 154 & TB 154
CVE-2026-74948
6.5 - Medium
- August 18, 2026
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Information Disclosure
Info Disclosure via Graphics:Text in Firefox/Thunderbird (pre-154)
CVE-2026-74945
6.5 - Medium
- August 18, 2026
Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Information Disclosure
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Mozilla Firefox or by Mozilla? Click the Watch button to subscribe.