Junglewise Threat Intelligence

CVE-2026-74964: Mozilla Firefox integer overflow in Graphics component

CVE-2026-74964 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird contain an integer overflow vulnerability in their Graphics rendering component. An attacker exploiting this flaw could achieve remote code execution or cause the browser to crash, disrupting users' work and potentially leading to data compromise or system compromise.

Technical details

An integer overflow vulnerability exists in the Graphics component of Firefox and Thunderbird. The vulnerability is triggered via network attack vector (malicious web content) and requires no user privileges. An attacker can craft malicious graphics data that causes integer overflow, leading to memory corruption. This can be leveraged for remote code execution or denial of service. The vulnerability has been fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 140.14 and before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR before 140.14 and before 153.1

Timeline

  • 2026-08-18: disclosed: CVE-2026-74964 disclosed in Mozilla Security Advisory MFSA2026-74
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14 and 153.1, Thunderbird 154, Thunderbird ESR 140.14 and 153.1

References

Related threats