Junglewise Threat Intelligence

CVE-2026-74943: Firefox use-after-free in Graphics: ImageLib

CVE-2026-74943 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird browsers contain a use-after-free vulnerability in their image rendering library that allows an attacker to execute arbitrary code when processing malicious images. This could enable unauthorized access to user data, credential theft, or installation of malware. The vulnerability affects widely-used browsers and was fixed in recent security updates.

Technical details

A use-after-free vulnerability exists in the Graphics: ImageLib component used by Firefox and Thunderbird for processing image data. The vulnerability occurs when memory is accessed after it has been freed, potentially allowing an attacker to corrupt the heap and achieve code execution. The attack vector is network-based—an attacker can trigger the vulnerability by crafting a malicious image and hosting it on a web page or delivering it via email. No special privileges or user interaction beyond viewing content is required. Patches are available in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR 115.x before 115.39, 140.x before 140.14, 153.x before 153.1
  • Mozilla Thunderbird before 154, 140.x before 140.14, 153.x before 153.1

Timeline

  • 2026-08-18: disclosed: Published by Mozilla
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1

References

Related threats