Description
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a side‑channel information disclosure in the Storage: Cache API component of Mozilla Firefox. An attacker can leverage this flaw to gain unintended access to private data held in the cache, such as HTTP response headers or sensitive cookies, thereby compromising confidentiality. The weakness is rooted in improper isolation of cached data across origins, facilitating covert data leakage.

Affected Systems

The issue affects versions of Mozilla Firefox that were released prior to the bug fix, specifically browsers updated before Firefox 154 and before Firefox ESR 153.1. Any installation of those earlier releases that includes the Storage: Cache API component is susceptible. The problem is not present in Firefox 154 and later, nor in ESR 153.1 and newer.

Risk and Exploitability

The EPSS score is unavailable, and the vulnerability is not listed in CISA's KEV catalog, indicating no confirmed exploit activity to date. Nonetheless, because the flaw relies on a side‑channel in browser storage that can be triggered by crafted web content, the attack vector is likely local within the user’s browser session. An attacker who can deliver malicious scripts to a user’s browser—such as through a compromised website or phishing—could exploit the vulnerability without needing elevated privileges, leading to potential confidentiality loss. The risk is elevated in environments where users access sensitive information through the Storage: Cache API.

Generated by OpenCVE AI on August 18, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 154 or newer, which contains the side‑channel fix for the Storage: Cache API component.
  • For Firefox ESR users, upgrade to version 153.1 or later.
  • If an immediate upgrade is not possible, restrict use of the Storage: Cache API to trusted origins or disable the feature entirely in applications that do not require it.

Generated by OpenCVE AI on August 18, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Information disclosure due to side-channel in the Storage: Cache API component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:37.219Z

Reserved: 2026-08-17T11:58:08.011Z

Link: CVE-2026-74954

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:32.360

Modified: 2026-08-18T13:17:32.360

Link: CVE-2026-74954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor