Executive brief
Firefox and Thunderbird are widely used web browsers and email clients relied upon by millions of users for secure communication and web browsing. A privilege escalation vulnerability in the Graphics component allows attackers to gain elevated system permissions and potentially compromise the browser sandbox, risking user data and system integrity.
Technical details
This privilege escalation vulnerability (CVE-2026-74947) stems from an invalid pointer dereference in the Graphics component. The vulnerability allows an attacker to escape browser sandbox restrictions and execute code with elevated privileges. It affects Firefox versions prior to 154, Firefox ESR versions prior to 153.1, and Thunderbird versions prior to 154 and 153.1. Attack vectors likely include malicious web content or crafted graphics rendering operations. The issue has been patched in the specified fixed versions.
Affected products
- Mozilla Firefox < 154
- Mozilla Firefox ESR < 153.1
- Mozilla Thunderbird < 153.1 and < 154
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1