Privilege Escalation Vulnerability in Firefox by Mozilla
CVE-2026-74949

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74949?

A privilege escalation vulnerability has been identified in the Graphics: Canvas2D component of Firefox, stemming from a use-after-free condition. This flaw could allow an attacker to execute unauthorized actions or access restricted resources within the web browser. Mozilla has addressed this vulnerability in recent updates, specifically in Firefox versions 154, Firefox ESR 140.14, and Firefox ESR 153.1. It is crucial for users to update their browsers to mitigate the potential risks associated with this vulnerability.

Affected Version(s)

Firefox 140.14

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

r00tdaddy
.