Information Disclosure in Firefox's Push Subscriptions Component
CVE-2026-74972

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74972?

A vulnerability exists in the Push Subscriptions component of Firefox that allows for potential information disclosure through the Document Object Model (DOM). Successful exploitation could lead to unauthorized data exposure. This issue has been addressed in Firefox version 154, and the ESR versions 140.14 and 153.1. Users are advised to update their browsers to these versions to mitigate potential risks.

Affected Version(s)

Firefox 140.14

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kagami Rosylight
.