Junglewise Threat Intelligence

CVE-2026-74952: Mozilla Firefox privilege escalation in Application Update component

CVE-2026-74952 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird contain a privilege escalation vulnerability in their automatic update mechanism. An attacker exploiting this flaw could gain elevated system privileges, potentially compromising the entire browser or system integrity. Mozilla has issued fixes in Firefox 154, Thunderbird 154, and their ESR variants.

Technical details

CVE-2026-74952 is a privilege escalation vulnerability in the Application Update component of Firefox and Thunderbird. The flaw allows an attacker to escalate privileges on the affected system by exploiting the application's update mechanism. While specific technical details are not fully disclosed in the available references, the moderate-to-high impact rating suggests the vulnerability requires specific preconditions or limited attack surface. Patches are available in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2. Users should apply these updates immediately to remediate the vulnerability.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Thunderbird before 154
  • Mozilla Firefox ESR before 153.2
  • Mozilla Thunderbird before 153.2

Timeline

  • 2026-08-18: disclosed: CVE-2026-74952 disclosed by Mozilla
  • 2026-08-18: patched: Fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2

References

Related threats