Executive brief
Firefox and Thunderbird are widely-used browsers and email clients that handle web requests and content. A privilege escalation vulnerability in the Request Handling component could allow an attacker to gain elevated system permissions, potentially compromising the entire system or enabling access to sensitive files and data that should be restricted from the user.
Technical details
CVE-2026-74955 is a privilege escalation vulnerability in the Request Handling component of Firefox and Thunderbird. The vulnerability allows an attacker to escalate privileges through maliciously-crafted requests, exploiting a flaw in how requests are handled and validated. Exploitation likely requires local access or user interaction. The vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. No active exploitation in the wild has been reported.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed: Published by Mozilla Foundation Security Advisory
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, Thunderbird 153.1