Same-origin Policy Bypass in Firefox Audio/Video Component
CVE-2026-74967

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74967?

A same-origin policy bypass vulnerability exists in the Audio/Video: Playback component of Firefox, which could allow an attacker to exploit this weakness to access potentially sensitive data across different origins. This flaw has been addressed in the updates for Firefox 154 and its Extended Support Release (ESR) variants, ensuring that users are protected from potential attacks leveraging this vulnerability.

Affected Version(s)

Firefox 140.14

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Mozilla Fuzzing Team
.