Privilege Escalation in Firefox Downloads API Component
CVE-2026-74950

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74950?

This vulnerability arises from a privilege escalation flaw within the Downloads API component of Firefox. An attacker exploiting this issue could gain elevated privileges, allowing unauthorized access to sensitive functions. The vulnerability was addressed in Firefox version 154 and Firefox ESR version 153.1, highlighting the importance of updating to the latest versions to mitigate risks.

Affected Version(s)

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Frederik Braun
.