Description
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to elevate privileges within the Firefox Downloads API component. By exploiting the flaw, an attacker could execute actions normally restricted to a more privileged user, potentially compromising the integrity of the browser and the data accessed through the download mechanism.

Affected Systems

Mozilla Firefox is affected. Versions prior to 154 and Firefox ESR versions prior to 153.1 contain the vulnerability.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the exploitation probability is not quantified. However, privilege escalation flaws are generally considered high-risk because they allow attackers to gain elevated capabilities. The likely attack vector is via malicious web content that interacts with the Downloads API, as the description does not specify an alternative path. Based on the nature of the flaw, the potential for local or browser-level code execution is plausible.

Generated by OpenCVE AI on August 18, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 154 or newer, or to ESR 153.1 or newer, to receive the official fix.
  • If an update is not immediately available, restrict the use of the Downloads API by disabling automatic downloads or enforcing user approval for download actions.
  • Continue monitoring Mozilla security advisories for additional mitigation guidance and apply future patches as they become available.

Generated by OpenCVE AI on August 18, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264
CWE-269

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Privilege escalation in the Downloads API component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:36.466Z

Reserved: 2026-08-17T11:57:59.669Z

Link: CVE-2026-74950

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:31.817

Modified: 2026-08-18T13:17:31.817

Link: CVE-2026-74950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses