Junglewise Threat Intelligence

CVE-2026-74960: Mozilla Firefox site isolation issue in WebExtensions

CVE-2026-74960 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's WebExtensions component contains a flaw that allows malicious code to escape site isolation protections, which are designed to prevent websites from accessing each other's data. An attacker could exploit this to steal sensitive information from other open websites or gain unauthorized access to user data across multiple sites.

Technical details

A site isolation issue exists in the Firefox WebExtensions component (CVE-2026-74960). Site isolation is a security boundary that prevents malicious websites from accessing data in other browser contexts. The vulnerability allows an attacker to bypass this isolation, potentially enabling cross-site data theft or privilege escalation within the browser sandbox. The flaw was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. No evidence of active exploitation in the wild has been reported.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 140.14 and 153.1
  • Mozilla Thunderbird before 154, 140.14, and 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Firefox 154, Firefox ESR 140.14 and 153.1, Thunderbird 154, 140.14, and 153.1

References

Related threats