Junglewise Threat Intelligence

CVE-2026-74954: Mozilla Firefox information disclosure in Storage Cache API

CVE-2026-74954 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's Storage Cache API component contains a side-channel vulnerability that could allow an attacker to infer sensitive information about cached data without direct access to it. This affects web browser security by potentially exposing user data or cached content that should remain private. The issue has been patched in recent versions of Firefox and Thunderbird.

Technical details

This vulnerability is a side-channel information disclosure in the Storage Cache API component, allowing attackers to infer sensitive data through timing analysis or other side-channel techniques. The attack is network-reachable and does not require authentication or special privileges. An attacker can exploit this to deduce information about cached content or user data. Mozilla released fixes in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird before 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, Thunderbird 153.1

References

Related threats