CVE-2026-74950 is a vulnerability in Mozilla Firefox
Published on August 18, 2026
Privilege escalation in the Downloads API component
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Products Associated with CVE-2026-74950
Want to know whenever a new CVE is published for Mozilla Firefox? stack.watch will email you.
Affected Versions
Mozilla Firefox:- Version 153.1, <= 153.* is unaffected.
- Version 154, <= * is unaffected.