Junglewise Threat Intelligence

CVE-2026-74945: Mozilla Firefox information disclosure in Graphics: Text

CVE-2026-74945 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox is a widely-used web browser that renders text and graphics on web pages. A flaw in the Graphics: Text component could allow attackers to access sensitive information that should not be visible to them. This could expose user data or system details through web content viewed in the browser.

Technical details

This vulnerability is an information disclosure flaw in the Graphics: Text component of Firefox. The vulnerability allows unauthorized access to sensitive information through improper handling in the text rendering subsystem. The attack vector is network-based, requiring user interaction (visiting a malicious web page). An attacker can achieve information disclosure by crafting a specially designed webpage that exploits the flaw. The vulnerability was addressed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, and corresponding versions of Thunderbird. Patches are available and users should update to the fixed versions.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR 115 before 115.39, 140 before 140.14, 153 before 153.1
  • Mozilla Thunderbird before 154, 140 before 140.14, 153 before 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, Thunderbird 153.1

References

Related threats