Junglewise Threat Intelligence

CVE-2026-74965: Mozilla Firefox privilege escalation in Shell Integration

CVE-2026-74965 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's Shell Integration component, which handles interactions between the browser and the operating system, contains a privilege escalation vulnerability that could allow a local attacker to execute code with elevated permissions. This could lead to unauthorized system access, installation of malware, or theft of sensitive user data stored on the computer.

Technical details

A privilege escalation vulnerability exists in the Shell Integration component of Firefox. The vulnerability allows an attacker with local access to escalate privileges within the browser or system context. While specific technical details are limited in the advisory, this class of vulnerability typically results from improper validation of system-level operations or insufficient isolation between privilege levels. The vulnerability affects Firefox versions prior to 154 and ESR versions prior to 140.14 and 153.1. Mozilla has released patches in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1 to address this issue.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 140.14 and 153.1
  • Mozilla Thunderbird before 154, 140.14, and 153.1

Timeline

  • 2026-08-18: disclosed: CVE-2026-74965 disclosed as part of Mozilla Security Advisory 2026-74
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1

References

Related threats