Junglewise Threat Intelligence

CVE-2026-74935: Mozilla Firefox privilege escalation in DOM: Networking component

CVE-2026-74935 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox is a widely-used web browser that handles network connections and DOM (Document Object Model) operations for displaying web pages. A privilege escalation vulnerability in the DOM: Networking component allows an attacker to gain elevated permissions within the browser, potentially leading to unauthorized access to sensitive user data or control over browser operations. This vulnerability affects multiple Firefox versions and related products.

Technical details

CVE-2026-74935 is a privilege escalation vulnerability in the DOM: Networking component of Firefox. The vulnerability affects Firefox 154 and earlier versions, as well as Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, and equivalent versions of Thunderbird. The attack vector is network-based, allowing a remote attacker to exploit this flaw through malicious web content. The vulnerability requires user interaction (visiting a malicious website) and can result in privilege escalation within the browser sandbox. Mozilla has released patches in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR 115 before 115.39, 140 before 140.14, 153 before 153.1
  • Mozilla Thunderbird before 154, 140 before 140.14, 153 before 153.1

Timeline

  • 2026-08-18: disclosed: CVE-2026-74935 published and Mozilla security advisory MFSA2026-74 released
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1

References

Related threats