Executive brief
Firefox and Thunderbird contain a same-origin policy bypass vulnerability in the image rendering component. This allows an attacker to potentially access resources from other websites, compromising user privacy and enabling cross-site data theft. The vulnerability affects multiple versions but has been patched.
Technical details
A same-origin policy bypass vulnerability exists in the Graphics: ImageLib component of Firefox and Thunderbird. The vulnerability allows an attacker to circumvent browser security controls that normally prevent websites from accessing resources or data from other origins. An attacker can craft a malicious webpage that exploits this flaw through network access without requiring user authentication or special privileges. Successful exploitation could lead to unauthorized access to cross-site resources and user data. The vulnerability has been patched in Firefox 154, Firefox ESR versions 115.39, 140.14, and 153.1, and Thunderbird versions 154, 140.14, and 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 115.39, 140.14, 153.1
- Mozilla Thunderbird before 154, 140.14, 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 115.39/140.14/153.1, Thunderbird 154/140.14/153.1