Executive brief
Firefox's Graphics component contains a site isolation issue that could allow malicious websites to access data or resources from other websites. Site isolation is a security boundary that prevents one website from interfering with another. An attacker could exploit this to steal sensitive information from other browser tabs or bypass security protections.
Technical details
A site isolation vulnerability exists in the Firefox Graphics component, as reported by Abdulaziz Alasaiqah. The vulnerability allows an attacker to bypass site isolation boundaries through a malicious web page delivered over the network. The attack does not require user authentication or special browser configuration. An attacker can exploit this to access data or resources intended for a different security origin. Mozilla has patched the issue in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed: Published in Mozilla Security Advisory 2026-74
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1