Junglewise Threat Intelligence

CVE-2026-74971: Mozilla Firefox information disclosure in DOM UI Events

CVE-2026-74971 · Severity: medium · CVSS 4.3 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird contain an information disclosure vulnerability in the DOM component that handles user interface events and focus management. An attacker could exploit this flaw to leak sensitive information from browser memory or cross-origin content, potentially exposing user credentials, browsing history, or personal data.

Technical details

CVE-2026-74971 is an information disclosure vulnerability in the DOM: UI Events & Focus Handling component, reported by avlidienbrunn. The vulnerability allows unauthorized access to sensitive information through the DOM's event handling and focus management mechanisms. The flaw was addressed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. The attack vector and specific preconditions have not been fully disclosed, but the moderate severity rating suggests the exploitation requires specific conditions or user interaction.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 140.14 and 153.1
  • Mozilla Thunderbird before 154, 140.14, and 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1

References

Related threats