Description
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An invalid pointer in the Graphics component of Mozilla Firefox allows an attacker to gain elevated privileges on the host system. The vulnerability arises from the improper handling of memory during graphics processing, enabling an attacker to execute code with the privileges of the browser process. This flaw can lead to full system compromise, as the browser typically runs with the user's credentials, and the memory corruption can be leveraged to escape sandbox controls.

Affected Systems

Versions of Firefox before 154 on the standard release channel and before 153.1 on the Extended Support Release (ESR) channel are impacted. The flaw exists across all platforms where the Graphics component is active, including Windows, macOS, and Linux distributions.

Risk and Exploitability

The CVSS score is not provided in the available data, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves local exploitation through graphics content rendering, such as images or web pages. While exploitation may require user interaction to trigger graphics processing, the potential for privileged code execution makes it a high‑severity risk for affected users.

Generated by OpenCVE AI on August 18, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 154 or later, or ESR 153.1 or later, to receive the patch that corrects the invalid pointer in the Graphics component.
  • If an immediate upgrade is not possible, limit exposure by sanitizing or restricting untrusted graphics content and, if supported, enforce stricter sandboxing to prevent the vulnerability from being triggered.
  • Continuously monitor Mozilla security advisories and apply any subsequent updates as they become available.

Generated by OpenCVE AI on August 18, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-416

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Privilege escalation due to invalid pointer in the Graphics component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:36.203Z

Reserved: 2026-08-17T11:57:53.297Z

Link: CVE-2026-74947

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:31.410

Modified: 2026-08-18T13:17:31.410

Link: CVE-2026-74947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses