Description
Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Safe Browsing component of Firefox allows an attacker to circumvent the browser’s protection mechanism, enabling malicious URLs or content to be accessed without triggering the usual safeguards. The vulnerability makes the Safe Browsing checks ineffective, potentially allowing phishing sites or malware downloads that would normally be blocked. Based on the description, the weakness likely involves improper validation of the Safe Browsing parameters, though the exact implementation flaw is not detailed in the alert.

Affected Systems

Mozilla Firefox browsers running versions prior to Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1, as well as Mozilla Thunderbird browsers running versions prior to Thunderbird 154, Thunderbird ESR 140.14, and Thunderbird ESR 153.1 are impacted. Users of these releases are at risk until they upgrade to the patched versions where the Safe Browsing bypass is fixed.

Risk and Exploitability

The EPSS score remains low (<1%) and the vulnerability is not listed in the CISA KEV catalog, indicating that publicly known exploitation activity is either low or undocumented. The CVSS score of 8.1 indicates high severity, reflecting the importance of the Safe Browsing component. Attackers would need to lure or trick users into visiting affected sites; the direct attack vector is web‑based and could be exercised from any site that a user visits using the default browser configuration. No public exploit code has been reported, but the low EPSS score means the risk remains relatively low, although the high CVSS indicates that if exploited, the impact could be significant to users.

Generated by OpenCVE AI on August 21, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Mozilla Firefox version 154 or the corresponding ESR releases (140.14 or 153.1) to receive the Safe Browsing fix.
  • Install Mozilla Thunderbird version 154 or the corresponding ESR releases (140.14 or 153.1) to receive the Safe Browsing fix.
  • If updating immediately is not feasible, disable the Safe Browsing feature through about:config or the privacy settings panel to block future exploitation of this bypass.
  • Maintain a routine update schedule for Firefox and Thunderbird and monitor Mozilla security advisories for any new information about related vulnerabilities.

Generated by OpenCVE AI on August 21, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4750-1 firefox-esr security update
Debian DLA Debian DLA DLA-4754-1 thunderbird security update
Debian DSA Debian DSA DSA-6451-1 firefox-esr security update
Debian DSA Debian DSA DSA-6461-1 thunderbird security update
History

Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-807
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Tue, 18 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Mitigation bypass in the Safe Browsing component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-21T20:05:28.562Z

Reserved: 2026-08-17T11:58:15.877Z

Link: CVE-2026-74957

cve-icon Vulnrichment

Updated: 2026-08-21T20:05:24.172Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:32.760

Modified: 2026-08-24T15:52:58.787

Link: CVE-2026-74957

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T12:23:31Z

Links: CVE-2026-74957 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T22:00:14Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision