Description
Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Safe Browsing component of Firefox allows an attacker to circumvent the browser’s protection mechanism, enabling malicious URLs or content to be accessed without triggering the usual safeguards. The vulnerability makes the Safe Browsing checks ineffective, potentially allowing phishing sites or malware downloads that would normally be blocked. Based on the description, the weakness likely involves improper validation of the Safe Browsing parameters, though the exact implementation flaw is not detailed in the alert.

Affected Systems

Mozilla Firefox browsers running versions prior to Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1 are impacted. Users of these releases are at risk until they upgrade to the patched versions where the Safe Browsing bypass is fixed.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating that publicly known exploitation activity is either low or undocumented. Consequently, the measured severity is unknown, but the potential impact is significant because Safe Browsing is a core defense against malicious web content. Attackers would need to lure or trick users into visiting affected sites; the direct attack vector is therefore web‑based and could be exercised from any site that a user visits by using the default browser configuration. No public exploit code has been reported, but the lack of an EPSS score means the risk is not well quantified.

Generated by OpenCVE AI on August 18, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Mozilla Firefox version 154 or the corresponding ESR releases (140.14 or 153.1) to receive the Safe Browsing fix.
  • If updating immediately is not feasible, disable the Safe Browsing feature through about:config or the privacy settings panel to block future exploitation of this bypass.
  • Maintain a routine update schedule for Firefox and monitor Mozilla security advisories for any new information about related vulnerabilities.

Generated by OpenCVE AI on August 18, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Mitigation bypass in the Safe Browsing component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:31.078Z

Reserved: 2026-08-17T11:58:15.877Z

Link: CVE-2026-74957

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:32.760

Modified: 2026-08-18T13:17:32.760

Link: CVE-2026-74957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses
  • CWE-20

    Improper Input Validation