Same-Origin Policy Bypass in Firefox by Mozilla
CVE-2026-74963

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74963?

This vulnerability in Firefox's Networking: Cookies component enables a same-origin policy bypass, which may lead to potential security risks. It allows attackers to exploit web applications by accessing restricted resources across different origins. Mozilla has addressed this issue in the 154 version of Firefox as well as in the Extended Support Release (ESR) versions 140.14 and 153.1, ensuring enhanced protection for users against possible exploitation.

Affected Version(s)

Firefox 140.14

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

5up3rh3i
.