Junglewise Threat Intelligence

CVE-2026-74961: Mozilla Firefox side-channel in Web Audio

CVE-2026-74961 · Severity: critical · CVSS 9.1 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's Web Audio component contains a side-channel vulnerability that could allow an attacker to infer sensitive information through timing analysis or other indirect methods. This could potentially expose user data or browser state without direct access. The vulnerability has been patched in Firefox 154 and related Mozilla products.

Technical details

This is a side-channel vulnerability in Firefox's Web Audio component (CVE-2026-74961), which enables timing or resource-based attacks to leak information despite access control mechanisms. The vulnerability is reachable from any website via standard Web Audio APIs without special privileges. An attacker can craft malicious web content to infer sensitive information through indirect observation of timing, cache behavior, or other covert channels. Mozilla classified the impact as moderate and fixed the issue in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird before 153.1

Timeline

  • 2026-08-18: disclosed: Published in Mozilla Security Advisory
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, Thunderbird 153.1

References

Related threats