Junglewise Threat Intelligence

CVE-2026-74968: Mozilla Firefox site isolation issue in WebRender graphics component

CVE-2026-74968 · Severity: medium · CVSS 5.4 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's graphics rendering engine (WebRender) contains a site isolation flaw that could allow content from one website to be accessed or interfered with by another website. This breaks the security boundary that prevents malicious sites from stealing data or credentials from other sites you visit. The issue affects Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR and was patched in recent versions.

Technical details

This vulnerability is a site isolation bypass in the Graphics: WebRender component, a critical security boundary mechanism that isolates renderer processes per-site to prevent cross-origin data access. The flaw allows an attacker to circumvent this isolation through the WebRender graphics subsystem, potentially gaining unauthorized access to content from other origins. The attack is reachable via network (malicious webpage), though full exploitation details are not publicly available. The vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR before 153.1

Timeline

  • 2026-08-18: disclosed: Published via Mozilla Security Advisory
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1

References

Related threats