Executive brief
Firefox and Thunderbird implement browser security controls to prevent websites from accessing each other's data. A same-origin policy bypass in the cookies component allows attackers to circumvent these controls, potentially enabling unauthorized access to user session cookies and sensitive data stored by other websites. This vulnerability affects multiple versions of Firefox and Thunderbird and was fixed in recent security updates.
Technical details
A same-origin policy bypass vulnerability exists in the Networking: Cookies component of Firefox and Thunderbird. The vulnerability allows an attacker to violate the same-origin policy mechanism that prevents one origin from accessing cookies or data belonging to another origin. The attack vector and specific technical prerequisites are not detailed in the available references, but the fix was deployed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. The vulnerability has not been reported as actively exploited in the wild.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 140.14 and before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 140.14 and before 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1