Junglewise Threat Intelligence

CVE-2026-74958: Mozilla Firefox information disclosure in WebRTC

CVE-2026-74958 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A WebRTC component in Firefox can leak sensitive information to websites, potentially exposing user data or internal network details. This vulnerability affects Firefox web browsers used by millions of users globally and could allow attackers to access confidential information through specially crafted web pages.

Technical details

CVE-2026-74958 is an information disclosure vulnerability in the WebRTC component of Firefox. The vulnerability allows unauthorized access to sensitive data through the WebRTC implementation. The attack vector is network-based and requires user interaction (visiting a malicious website). Affected users running vulnerable versions of Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR are at risk of data exposure. The vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR before 153.1

Timeline

  • 2026-08-18: disclosed: CVE-2026-74958 disclosed
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1

References

Related threats