Same-Origin Policy Bypass in Firefox by Mozilla
CVE-2026-74956

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74956?

This vulnerability involves a bypass of the same-origin policy within the Service Workers component of Firefox, allowing potential unauthorized access to sensitive information across different origins. The issue primarily affects specific versions of Firefox but has been addressed in the updates provided in versions 154 and Firefox ESR 153.1. Users are encouraged to update their browsers to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pakhunov.anton.n
.