CVE-2026-75874
NixOS Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-75874 is a sandbox escape vulnerability in the Remote Settings Client component of Mozilla Firefox and Thunderbird. Discovered and reported by researcher "crixer," it was publicly disclosed on August 18, 2026, as part of Mozilla Foundation Security Advisories MFSA2026-74 (Firefox) and MFSA2026-78 (Thunderbird). All versions of Firefox and Thunderbird prior to version 154 are affected. It carries a CVSS v3.1 base score of 10.0 (Critical), reflecting its network-accessible, unauthenticated, no-user-interaction attack profile with a changed scope (Mozilla Advisory, Mozilla Advisory).

Détails techniques

The vulnerability is classified under CWE-693 (Protection Mechanism Failure), indicating that the Remote Settings Client component fails to properly enforce sandbox restrictions, allowing code executing within the browser sandbox to escape into the host environment. The attack vector is network-based, requires no authentication, no privileges, and no user interaction, making it automatable and highly dangerous. The specific flaw resides in how the Remote Settings Client processes data, though the full technical details remain restricted in the Mozilla bug tracker (Bug 2039972). The vulnerability maps to CAPEC patterns including CAPEC-237 (Escaping a Sandbox by Calling Code in Another Language) and CAPEC-480 (Escaping Virtualization) (Mozilla Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to break out of the Firefox or Thunderbird sandbox and execute arbitrary code with the privileges of the browser process on the host system. The CVSS score reflects total technical impact — full confidentiality, integrity, and availability compromise — with a changed scope, meaning the impact extends beyond the browser sandbox to the underlying operating system. This could enable an attacker to access sensitive user data, install malware, establish persistence, or pivot to other systems on the network. For Thunderbird, Mozilla notes the flaw is not exploitable via email (since scripting is disabled when reading mail), but it is a risk in browser-like contexts (Mozilla Advisory, Mozilla Advisory).

Exploitabilité

As of the disclosure date (August 18, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the vulnerability is rated automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction, significantly raising the risk of future weaponization. No threat actor attribution has been reported at this time.

Atténuation et solutions de contournement

Mozilla has released patches addressing this vulnerability in Firefox 154 and Thunderbird 154, both announced on August 18, 2026. Users and administrators should update to these versions immediately. No configuration-based workarounds have been published by Mozilla; upgrading to the patched release is the only recommended remediation. Enterprise administrators should prioritize deployment via their software management tooling and monitor Mozilla security advisories for any further updates (Mozilla Advisory, Mozilla Advisory).

Réactions de la communauté

The vulnerability received coverage from security monitoring organizations including AusCERT (ESB-2026.9671) and the Western Australian Government SOC (advisory 20260819001), both issuing alerts on August 19, 2026. Community discussion appeared on Reddit's r/pwnhub in a CVE daily brief. Kaspersky also catalogued the vulnerability (KLA91226). No notable independent researcher commentary or major media coverage beyond standard advisory aggregation has been identified at this time.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté NixOS Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • firefox
NonOuiAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • rhel10::firefox-flatpak
NonOuiAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NonOuiAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NonOuiAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NonOuiAug 18, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités