CVE-2026-75874
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-75874 is a sandbox escape vulnerability in the Remote Settings Client component of Mozilla Firefox and Thunderbird. Discovered and reported by researcher "crixer," it was publicly disclosed on August 18, 2026, as part of Mozilla Foundation Security Advisories MFSA2026-74 (Firefox) and MFSA2026-78 (Thunderbird). All versions of Firefox and Thunderbird prior to version 154 are affected. It carries a CVSS v3.1 base score of 10.0 (Critical), reflecting its network-accessible, unauthenticated, no-user-interaction attack profile with a changed scope (Mozilla Advisory, Mozilla Advisory).

Technical details

The vulnerability is classified under CWE-693 (Protection Mechanism Failure), indicating that the Remote Settings Client component fails to properly enforce sandbox restrictions, allowing code executing within the browser sandbox to escape into the host environment. The attack vector is network-based, requires no authentication, no privileges, and no user interaction, making it automatable and highly dangerous. The specific flaw resides in how the Remote Settings Client processes data, though the full technical details remain restricted in the Mozilla bug tracker (Bug 2039972). The vulnerability maps to CAPEC patterns including CAPEC-237 (Escaping a Sandbox by Calling Code in Another Language) and CAPEC-480 (Escaping Virtualization) (Mozilla Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to break out of the Firefox or Thunderbird sandbox and execute arbitrary code with the privileges of the browser process on the host system. The CVSS score reflects total technical impact — full confidentiality, integrity, and availability compromise — with a changed scope, meaning the impact extends beyond the browser sandbox to the underlying operating system. This could enable an attacker to access sensitive user data, install malware, establish persistence, or pivot to other systems on the network. For Thunderbird, Mozilla notes the flaw is not exploitable via email (since scripting is disabled when reading mail), but it is a risk in browser-like contexts (Mozilla Advisory, Mozilla Advisory).

Exploitability

As of the disclosure date (August 18, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the vulnerability is rated automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction, significantly raising the risk of future weaponization. No threat actor attribution has been reported at this time.

Mitigation and workarounds

Mozilla has released patches addressing this vulnerability in Firefox 154 and Thunderbird 154, both announced on August 18, 2026. Users and administrators should update to these versions immediately. No configuration-based workarounds have been published by Mozilla; upgrading to the patched release is the only recommended remediation. Enterprise administrators should prioritize deployment via their software management tooling and monitor Mozilla security advisories for any further updates (Mozilla Advisory, Mozilla Advisory).

Community reactions

The vulnerability received coverage from security monitoring organizations including AusCERT (ESB-2026.9671) and the Western Australian Government SOC (advisory 20260819001), both issuing alerts on August 19, 2026. Community discussion appeared on Reddit's r/pwnhub in a CVE daily brief. Kaspersky also catalogued the vulnerability (KLA91226). No notable independent researcher commentary or major media coverage beyond standard advisory aggregation has been identified at this time.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • rhel10::firefox-flatpak
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management