Executive brief
Firefox and Thunderbird contain a site isolation flaw in the CSS parsing component that could allow a malicious website to access data from other browser tabs or windows. This vulnerability affects the browser's core security mechanism that separates content from different websites, potentially enabling cross-site data theft. Mozilla has released patches in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1 to address this issue.
Technical details
This is a site isolation bypass vulnerability in the CSS Parsing and Computation component affecting Mozilla Firefox and Thunderbird. The flaw allows an attacker to break the browser's site isolation boundaries through specially crafted CSS, potentially enabling access to sensitive data from other origins. The vulnerability requires no special user interaction beyond visiting a malicious website and is remotely exploitable over the network. An attacker can exploit this to read cross-origin data or perform actions on behalf of the user on other websites. Fixes are available in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1