Executive brief
Firefox's Form Autofill feature, which stores and auto-populates saved credentials and personal information on web forms, contains a flaw that can expose sensitive user data. An attacker could exploit this vulnerability to reveal personal information that users believed was securely stored, potentially leading to identity theft or fraud.
Technical details
CVE-2026-74966 is an information disclosure vulnerability in the Form Autofill component of Firefox. The vulnerability allows unauthorized access to stored autofill data through the web rendering engine. The flaw was identified by the Mozilla Fuzzing Team and patched in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. The attack likely requires local or adjacent-network access to the browser process or interaction with a malicious webpage to trigger the information leak.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed: Vulnerability announced by Mozilla
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1