Junglewise Threat Intelligence

CVE-2026-74970: Mozilla Firefox site isolation issue in Graphics component

CVE-2026-74970 · Severity: medium · CVSS 5.4 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's Graphics component contains a site isolation issue that could allow malicious websites to access data or resources from other websites. Site isolation is a security boundary that prevents one website from interfering with another. An attacker could exploit this to steal sensitive information from other browser tabs or bypass security protections.

Technical details

A site isolation vulnerability exists in the Firefox Graphics component, as reported by Abdulaziz Alasaiqah. The vulnerability allows an attacker to bypass site isolation boundaries through a malicious web page delivered over the network. The attack does not require user authentication or special browser configuration. An attacker can exploit this to access data or resources intended for a different security origin. Mozilla has patched the issue in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird before 153.1

Timeline

  • 2026-08-18: disclosed: Published in Mozilla Security Advisory 2026-74
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1

References

Related threats