Improper access control in Mozilla products - CVE-2026-74934
Published: August 18, 2026
Vulnerability identifier: #VU144045
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74934
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to bypass site isolation.
Affected software
Mozilla Firefox
Firefox ESR
Firefox for Android
Firefox ESR
Firefox for Android
How to mitigate CVE-2026-74934
Install security update from vendor's website.
Mozilla Firefox - update to 154.0
Firefox for Android - update to 154.0
Firefox ESR - addressed in versions 115.39.0, 140.14.0, 153.1.0
Firefox for Android - update to 154.0
Firefox ESR - addressed in versions 115.39.0, 140.14.0, 153.1.0
External References
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-75/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050584