Executive brief
Firefox's Graphics component contains a race condition that can lead to use-after-free memory errors. An attacker could exploit this vulnerability to crash the browser or potentially execute arbitrary code, affecting the stability and security of users' browsing sessions.
Technical details
CVE-2026-74973 is a race condition vulnerability in Firefox's Graphics component that results in a use-after-free condition. The vulnerability is triggered during graphics rendering operations and can be exploited via network when a user visits a malicious webpage. An attacker can cause memory corruption that leads to application crash or potential code execution. The vulnerability has been patched in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.1, and corresponding versions of Thunderbird.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR 115.38 and earlier, 140.0
- Mozilla Thunderbird before 154, 140.13 and earlier, 153.0
Timeline
- 2026-08-18: disclosed: CVE-2026-74973 disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.1, Thunderbird 154, Thunderbird 140.14, Thunderbird 153.1