Executive brief
Firefox and Thunderbird handle web notifications via a Push Subscriptions component that leaked sensitive information. An attacker could exploit this to disclose data related to push notification subscriptions, potentially exposing user activity or service URLs. Mozilla has patched this in Firefox 154, Firefox ESR 140.14, Thunderbird 154, and related versions.
Technical details
This vulnerability is an information disclosure flaw in the DOM Push Subscriptions component of Firefox and Thunderbird. The root cause involved improper handling of subscription data, allowing sensitive information to be exposed to attackers. The attack requires network access but no authentication. An attacker could extract push subscription details, potentially revealing user activity or notification service identifiers. The fix was released in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR 140.13 and earlier, 153.0
- Mozilla Thunderbird before 154
- Mozilla Thunderbird 140.13 and earlier, 153.0
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, Thunderbird 153.1