Same-Origin Policy Bypass in Firefox by Mozilla
CVE-2026-74974

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74974?

A vulnerability exists in the Graphics: ImageLib component of Firefox that allows attackers to bypass the same-origin policy, potentially leading to unauthorized access to web content. This could enable exploitation by allowing malicious web pages to interact with resources from another domain in an unintended manner. The issue has been addressed in several Firefox updates, emphasizing the importance of keeping your browser up to date to mitigate potential risks.

Affected Version(s)

Firefox 115.39

Firefox 140.14

Firefox 153.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Mozilla Fuzzing Team
.