Site Isolation Vulnerability in Mozilla Firefox WebExtensions
CVE-2026-74960

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74960?

A site isolation issue has been identified in the WebExtensions component of Mozilla Firefox. This vulnerability could potentially allow for cross-site data leakage, where malicious web pages can access data from other sites. The issue has been addressed in the latest updates, Mozilla Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1, ensuring that users can maintain their privacy and security integrity while browsing.

Affected Version(s)

Firefox 140.14

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khanh Nguyen
.