Junglewise Threat Intelligence

CVE-2026-74981: Mozilla Firefox site isolation issue in Web Codecs

CVE-2026-74981 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox's Web Codecs component has a site isolation flaw that could allow malicious websites to access content from other sites. An attacker could exploit this to steal sensitive information from other tabs or applications open in the browser. The vulnerability affects Firefox and Thunderbird across multiple versions and has been patched in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Technical details

This vulnerability is a site isolation bypass in the Audio/Video: Web Codecs component of Firefox. Site isolation is a security boundary that prevents one website from accessing content or state from another. The root cause involves improper isolation enforcement in the web codecs handling, allowing cross-site access. The vulnerability is network-reachable and can be triggered by a user visiting a malicious webpage; no special authentication or user interaction beyond normal browsing is required. An attacker can achieve cross-site information disclosure by exploiting the site isolation weakness. Patches are available in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 153.1

Timeline

  • 2026-08-18: disclosed: Published on NVD and Mozilla Security Advisory
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1

References

Related threats