Junglewise Threat Intelligence

CVE-2026-74967: Mozilla Firefox same-origin policy bypass in audio/video playback

CVE-2026-74967 · Severity: medium · CVSS 5.4 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird contain a same-origin policy bypass vulnerability in the audio and video playback component. An attacker could potentially bypass security restrictions to access cross-origin media content that should be blocked by browser security policies. This could lead to unauthorized access to sensitive audio or video data from other websites or services.

Technical details

This vulnerability is a same-origin policy bypass in the Audio/Video: Playback component of Firefox and Thunderbird. The vulnerability allows attackers to circumvent the same-origin policy, which is a fundamental browser security mechanism designed to prevent scripts from one origin from accessing data from another origin. The exact attack vector and preconditions are not fully disclosed in the available advisory, but the flaw was identified by The Mozilla Fuzzing Team. The vulnerability has been patched in Firefox 154, Firefox ESR 140.14 and 153.1, and Thunderbird 154, 140.14, and 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 140.14 and 153.1
  • Mozilla Thunderbird before 154, 140.14, and 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14 and 153.1, Thunderbird 154, 140.14, and 153.1

References

Related threats