CVE-2026-74958
NixOS Schwachstellenanalyse und -minderung

Überblick

CVE-2026-74958 is an information disclosure vulnerability in the WebRTC component of Mozilla Firefox and Thunderbird. Discovered and reported by Tomoya Nakanishi, it was publicly disclosed on August 18, 2026, as part of Mozilla's coordinated security release. Affected products include Firefox prior to version 154, Firefox ESR prior to version 153.1, Thunderbird prior to version 154, and Thunderbird ESR prior to version 153.1. It carries a CVSS v3.1 base score of 7.5 (High) (Mozilla Advisory, Mozilla Advisory).

Technische Details

The vulnerability is classified under CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), which is associated with attack patterns such as clickjacking and iFrame overlay abuse (CAPEC-103, CAPEC-222). The flaw resides in the WebRTC component and results in unintended information disclosure, exploitable remotely over the network without authentication or user interaction, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). The underlying bug is tracked as Mozilla Bug 2045368, though the bug report is access-restricted (Mozilla Advisory, Mozilla Advisory).

Aufprall

Successful exploitation of CVE-2026-74958 results in a high confidentiality impact, with no effect on integrity or availability. An unauthenticated remote attacker could leverage the WebRTC component flaw to disclose sensitive information from affected Firefox or Thunderbird instances, potentially exposing user data or session-related information processed through WebRTC communications. The scope is limited to the affected application and does not indicate lateral movement or system-level compromise based on available information (Mozilla Advisory, Mozilla Advisory).

Ausnutzbarkeit

As of the disclosure date (August 18, 2026), there is no evidence of in-the-wild exploitation, no known public proof-of-concept exploit code, and no threat actor attribution. The EPSS score is reported as 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment notes the vulnerability is automatable but has no known exploitation (Mozilla Advisory).

Risikominderung und Problemumgehungen

Mozilla has released patched versions addressing this vulnerability: Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird ESR 153.1. Users and administrators should update to these versions or later immediately. No configuration-based workarounds have been published; upgrading to a fixed release is the only recommended remediation (Mozilla Advisory, Mozilla Advisory).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt NixOS Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-74956CRITICAL9.1
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NeinJaAug 18, 2026
CVE-2026-74965HIGH8.8
  • NixOS logoNixOS
  • thunderbird
NeinJaAug 18, 2026
CVE-2026-74955HIGH8.8
  • NixOS logoNixOS
  • thunderbird
NeinJaAug 18, 2026
CVE-2026-74958HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NeinJaAug 18, 2026
CVE-2026-74963MEDIUM5.4
  • NixOS logoNixOS
  • thunderbird
NeinJaAug 18, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement