Executive brief
Firefox includes a Safe Browsing feature that protects users from visiting malicious websites and downloading harmful files. A mitigation bypass in this component could allow attackers to circumvent these protections, potentially exposing users to malware, phishing, or other web-based threats without their knowledge.
Technical details
This vulnerability is a mitigation bypass in Firefox's Safe Browsing component (CVE-2026-74957). The Safe Browsing system relies on security checks to block access to known malicious URLs and downloads. A bypass in these mitigation mechanisms would allow an attacker to craft requests or content that evade the safety checks, enabling delivery of malware or phishing content to unsuspecting users. The vulnerability affects Firefox, Firefox ESR, and Thunderbird browsers. Patches are available in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR 140.x before 140.14, 153.x before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird 140.x before 140.14, 153.x before 153.1
Timeline
- 2026-08-18: disclosed