Buffer overflow in Mozilla products - CVE-2026-74990

 

Buffer overflow in Mozilla products - CVE-2026-74990

Published: August 18, 2026


Vulnerability identifier: #VU144057
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74990
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when rendering content or handling browser operations. A remote attacker can trigger crafted browser interactions to execute arbitrary code.

Multiple internally found bugs are covered by this entry, and the advisory notes that some showed evidence of memory corruption or another security-relevant defect.


Affected software

Mozilla Firefox
Firefox ESR
Firefox for Android

How to mitigate CVE-2026-74990

Install security update from vendor's website.

Mozilla Firefox - update to 154.0
Firefox for Android - update to 154.0
Firefox ESR - addressed in versions 115.39.0, 140.14.0, 153.1.0

External References

Related Security Bulletins