Executive brief
Firefox's Web Audio component contains a side-channel vulnerability that could allow an attacker to infer sensitive information through timing analysis or other indirect methods. This could potentially expose user data or browser state without direct access. The vulnerability has been patched in Firefox 154 and related Mozilla products.
Technical details
This is a side-channel vulnerability in Firefox's Web Audio component (CVE-2026-74961), which enables timing or resource-based attacks to leak information despite access control mechanisms. The vulnerability is reachable from any website via standard Web Audio APIs without special privileges. An attacker can craft malicious web content to infer sensitive information through indirect observation of timing, cache behavior, or other covert channels. Mozilla classified the impact as moderate and fixed the issue in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed: Published in Mozilla Security Advisory
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, Thunderbird 153.1