Privilege Escalation Vulnerability in Firefox and Firefox ESR
CVE-2026-74985

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74985?

A privilege escalation vulnerability exists in the Enterprise Policies component of Firefox. This flaw allows attackers to exploit the browser's capabilities, potentially gaining unauthorized access or control over user privileges. Mozilla addressed this issue by releasing updates in Firefox version 154 and Firefox ESR 153.1. Users are encouraged to update their browsers to the latest versions to mitigate any risks associated with this vulnerability.

Affected Version(s)

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Mozilla Fuzzing Team
.