Information Disclosure in Firefox's Push Subscriptions Component
CVE-2026-74972
Currently unrated
What is CVE-2026-74972?
A vulnerability exists in the Push Subscriptions component of Firefox that allows for potential information disclosure through the Document Object Model (DOM). Successful exploitation could lead to unauthorized data exposure. This issue has been addressed in Firefox version 154, and the ESR versions 140.14 and 153.1. Users are advised to update their browsers to these versions to mitigate potential risks.
Affected Version(s)
Firefox 140.14
Firefox 153.1
Firefox 154