Buffer overflow in Mozilla products - CVE-2026-74987

 

Buffer overflow in Mozilla products - CVE-2026-74987

Published: August 18, 2026


Vulnerability identifier: #VU144075
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74987
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.

The advisory states that some of the internally found bugs showed evidence of memory corruption or another security-relevant defect.


Affected software

Firefox ESR
Mozilla Firefox
Firefox for Android

How to mitigate CVE-2026-74987

Install security update from vendor's website.

Firefox ESR - addressed in versions 140.14.0, 153.1.0
Firefox for Android - update to 154.0
Mozilla Firefox - update to 154.0

External References

Related Security Bulletins