Junglewise Threat Intelligence

CVE-2026-74953: Mozilla Firefox privilege escalation in Networking: Cookies

CVE-2026-74953 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird handle HTTP cookies as part of their core networking functionality, storing authentication tokens and session data critical to user security. A privilege escalation flaw in this component allows an attacker with network access to bypass security boundaries and gain elevated permissions within the browser process, potentially leading to unauthorized access to sensitive user data or malicious code execution.

Technical details

CVE-2026-74953 is a privilege escalation vulnerability in Firefox and Thunderbird's Networking: Cookies component, fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153. The vulnerability allows an attacker to escalate privileges within the browser security model, likely through improper validation or enforcement of cookie-related access controls. The attack vector and specific root cause are not fully detailed in available public sources, but the fix was deployed across both ESR (Extended Support Release) and stable channels in August 2026. No evidence of in-the-wild exploitation was reported at the time of disclosure.

Affected products

  • Mozilla Firefox Before 154
  • Mozilla Firefox ESR Before 140.14 and 153
  • Mozilla Thunderbird Before 154
  • Mozilla Thunderbird ESR Before 140.14 and 153

Timeline

  • 2026-08-18: disclosed: CVE-2026-74953 disclosed in Mozilla Foundation Security Advisory 2026-74
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153

References

Related threats