Site Isolation Flaw in Firefox's CSS Parsing Component
CVE-2026-74986

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74986?

A site isolation vulnerability exists within the CSS Parsing and Computation component of Firefox that could potentially allow malicious sites to execute unwanted actions on behalf of a user. This vulnerability was addressed in the most recent updates, specifically Firefox version 154 and Firefox ESR version 153.1. Users are encouraged to stay updated for enhanced security.

Affected Version(s)

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

5up3rh3i
.