Junglewise Threat Intelligence

CVE-2026-74977: Mozilla Firefox integer overflow in Graphics component

CVE-2026-74977 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird contain an integer overflow vulnerability in their Graphics component that could allow an attacker to cause a denial of service or potentially execute arbitrary code. This affects users of the browser and email client across Windows, macOS, and Linux systems. Mozilla has released patches in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1 to address the issue.

Technical details

An integer overflow flaw exists in the Graphics component (CVE-2026-74977) affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The vulnerability stems from insufficient bounds checking on integer operations within graphics rendering code. Exploitation requires a user to visit a malicious website or open a crafted document, but no additional authentication is needed. A successful attack could lead to memory corruption, denial of service, or arbitrary code execution within the browser or email client's security context. The vulnerability has been patched and fixed versions are available; users should update immediately.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR before 153.1

Timeline

  • 2026-08-18: disclosed: CVE-2026-74977 disclosed
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird ESR 153.1

References

Related threats