Executive brief
Firefox's Remote Settings Client component contains a privilege escalation vulnerability that could allow an attacker with network access to bypass security boundaries and execute code with elevated privileges. This affects Firefox's ability to securely manage and deploy configuration updates, potentially compromising the browser's security model and user data protection.
Technical details
CVE-2026-74942 is a privilege escalation vulnerability in Firefox's Remote Settings Client component, the system responsible for managing remote configuration and policy updates. The vulnerability allows an attacker to bypass security restrictions and gain elevated privileges within the browser context. The attack vector and specific preconditions are not detailed in available sources, but the high CVSS score of 8.8 suggests a remotely exploitable issue with significant impact. The vulnerability was patched in Firefox 154 (released August 18, 2026), Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR 115.x before 115.39; 140.x before 140.14; 153.x before 153.1
- Mozilla Thunderbird before 154; 140.x before 140.14; 153.x before 153.1
Timeline
- 2026-08-18: disclosed: CVE-2026-74942 disclosed by Mozilla Security Advisory
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 115.39, 140.14, 153.1, and Thunderbird 154, 140.14, 153.1