Executive brief
Firefox's Downloads API component contains a privilege escalation vulnerability that could allow an attacker to gain elevated system permissions. This vulnerability affects the browser's file download handling system and has been patched in the latest versions of Firefox and related Mozilla products.
Technical details
CVE-2026-74950 is a privilege escalation vulnerability in the Downloads API component of Mozilla Firefox and related products. The vulnerability allows an attacker to escalate privileges through improper handling in the Downloads API. The attack vector and specific preconditions are not detailed in available sources, but the vulnerability has been addressed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. Users should update to these patched versions to remediate the issue.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed: Mozilla Security Advisory 2026-74 published
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1