Description
Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a site isolation flaw in the Networking: Cookies component of Mozilla browsers. It is inferred that this flaw allows a web origin to read cookies from another origin, which could expose session identifiers or other sensitive data, potentially enabling session hijacking or unauthorized data exposure. The issue affects any version of Firefox or Thunderbird older than the patched releases (Firefox 154, ESR 140.14, ESR 153.1, Thunderbird 154, Thunderbird 140.14, Thunderbird 153.1). The likelihood of exploitation relies on a malicious web page or script that can trigger the unsafe cookie access. The attack vector and impact details are inferred from the description. This weakness is classified as CWE-1100 and CWE-346.

Affected Systems

Mozilla Firefox users operating on any version preceding Firefox 154, Firefox ESR 140.14, or Firefox ESR 153.1 are affected. Mozilla Thunderbird users on any version preceding Thunderbird 154, Thunderbird 140.14, or Thunderbird 153.1 are also affected. This includes all mainstream releases up to Firefox 153 and all ESR streams older than the specified patch versions.

Risk and Exploitability

Exploitation would likely involve a malicious web page or script that can read cookies from another site context, exposing session identifiers and sensitive data. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 8.1 indicates a high severity level. The attack vector is inferred to be a malicious web page that triggers unsafe cookie access, relying on the missing isolation guarantees of the Networking: Cookies component.

Generated by OpenCVE AI on August 21, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Mozilla Firefox (v154) or newer ESR release that contains the patch for the site isolation flaw identified by CWE-1100 and CWE-346.
  • If an immediate update cannot be performed, use the most recent ESR release that includes these fixes to mitigate the risk until a full update is possible.
  • Enforce strict cookie policies via the browser’s privacy settings or reputable extensions to limit cross‑site cookie access, reducing the impact of potential data leakage.

Generated by OpenCVE AI on August 21, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4750-1 firefox-esr security update
Debian DLA Debian DLA DLA-4754-1 thunderbird security update
Debian DSA Debian DSA DSA-6451-1 firefox-esr security update
Debian DSA Debian DSA DSA-6461-1 thunderbird security update
History

Fri, 21 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1100
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Site isolation issue in the Networking: Cookies component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-19T12:52:57.196Z

Reserved: 2026-08-17T11:58:26.320Z

Link: CVE-2026-74962

cve-icon Vulnrichment

Updated: 2026-08-19T12:51:49.083Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:33.430

Modified: 2026-08-19T16:38:05.230

Link: CVE-2026-74962

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T12:23:31Z

Links: CVE-2026-74962 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:00:13Z

Weaknesses
  • CWE-1100

    Insufficient Isolation of System-Dependent Functions

  • CWE-346

    Origin Validation Error