Executive brief
Firefox, a widely-used web browser that processes untrusted content from the internet, contains a same-origin policy bypass vulnerability in its Service Workers component. An attacker could exploit this to access sensitive data or perform actions on behalf of users across different websites, compromising the fundamental security model that isolates web applications from each other.
Technical details
A same-origin policy bypass in the DOM: Service Workers component allows an attacker to circumvent the browser's same-origin policy, which normally prevents scripts from one origin from accessing data belonging to another origin. The vulnerability is triggered through crafted Service Worker requests or manipulation of Service Worker state. An attacker with network access can craft malicious web content that, when visited by a user, exploits this flaw to access cross-origin data or perform unauthorized actions. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected products
- Mozilla Firefox below 154
- Mozilla Firefox ESR below 153.1
- Mozilla Thunderbird below 154
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1