Executive brief
Firefox and Thunderbird contain a privilege escalation vulnerability in their automatic update mechanism. An attacker exploiting this flaw could gain elevated system privileges, potentially compromising the entire browser or system integrity. Mozilla has issued fixes in Firefox 154, Thunderbird 154, and their ESR variants.
Technical details
CVE-2026-74952 is a privilege escalation vulnerability in the Application Update component of Firefox and Thunderbird. The flaw allows an attacker to escalate privileges on the affected system by exploiting the application's update mechanism. While specific technical details are not fully disclosed in the available references, the moderate-to-high impact rating suggests the vulnerability requires specific preconditions or limited attack surface. Patches are available in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2. Users should apply these updates immediately to remediate the vulnerability.
Affected products
- Mozilla Firefox before 154
- Mozilla Thunderbird before 154
- Mozilla Firefox ESR before 153.2
- Mozilla Thunderbird before 153.2
Timeline
- 2026-08-18: disclosed: CVE-2026-74952 disclosed by Mozilla
- 2026-08-18: patched: Fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2