Executive brief
Firefox, a widely-used web browser, contains a vulnerability in its Widget component that can be exploited to cause a denial-of-service condition. An attacker can crash or hang the browser, disrupting user productivity and potentially exposing the system to follow-up attacks.
Technical details
CVE-2026-74982 is a denial-of-service vulnerability in the Widget component of Mozilla Firefox and related products. The vulnerability can be triggered remotely over the network without requiring user authentication or special preconditions beyond visiting a malicious web page. A successful exploit causes the application to crash or become unresponsive, denying service to the user. The vulnerability was patched in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. No active exploitation in the wild has been reported at the time of publication.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1