Executive brief
Firefox's Add-ons Manager contains a security mitigation that can be bypassed by an attacker with network access, potentially allowing them to circumvent protections designed to prevent malicious extensions from being installed or executed. This could enable unauthorized code execution within the browser context and compromise user data and system security.
Technical details
This is a mitigation bypass vulnerability in Firefox's Add-ons Manager component (CVE-2026-74979). The vulnerability allows an attacker to circumvent security mechanisms that protect against malicious extension installation or execution. The flaw is exploitable over the network without requiring user authentication or special privileges. The vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed: Publicly disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1