Junglewise Threat Intelligence

CVE-2026-74983: Mozilla Firefox mitigation bypass in Data Loss Prevention

CVE-2026-74983 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird contain a vulnerability in their Data Loss Prevention feature that can be bypassed by an attacker, potentially allowing sensitive data to leak despite the protection mechanism being in place. This affects users of Firefox and Thunderbird who rely on this feature to prevent accidental or malicious data exfiltration. Mozilla has patched this issue in recent versions of both applications.

Technical details

The vulnerability is a mitigation bypass in Firefox and Thunderbird's Data Loss Prevention component (CVE-2026-74983). The specific attack vector and preconditions are not fully disclosed in the available advisory materials, but the CVSS 8.1 score indicates significant impact potential. The vulnerability was patched in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. Users should upgrade to these patched versions immediately.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 140.14 and before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR before 140.14 and before 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1

References

Related threats