Executive brief
Firefox's graphics rendering engine contained a vulnerability that could leak sensitive information from memory to a remote attacker. An attacker could craft a malicious webpage or graphics content to extract data from the browser's memory, potentially exposing user information. Firefox has patched this issue in recent versions.
Technical details
CVE-2026-74948 is an information disclosure vulnerability in Mozilla Firefox's Graphics component. The vulnerability allows an attacker to read sensitive data from memory through crafted graphics content or web pages. The attack is delivered via network (malicious website) and requires no special privileges or user authentication. An attacker can exploit this to leak sensitive information from the browser process memory. The vulnerability has been fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 115.39, before 140.14, before 153.1
- Mozilla Thunderbird before 154, before 140.14, before 153.1
Timeline
- 2026-08-18: disclosed: CVE-2026-74948 published by Mozilla
- 2026-08: patched: Fixed in Firefox 154, Firefox ESR 115.39, 140.14, 153.1, Thunderbird 154, 140.14, 153.1