Description
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug permits a web page to bypass the browser’s same-origin policy within the Networking: Cookies component. The flaw can potentially allow an attacker to interact with cookies that belong to different origins, which could expose session tokens or other sensitive information. The vulnerability was addressed in Firefox 154, ESR 140.14, ESR 153.1, and Thunderbird 154, 140.14, 153.1.

Affected Systems

Mozilla Firefox versions up to and including 154, ESR 140.14, and ESR 153.1 are affected. Thunderbird releases up to and including 154, 140.14, and 153.1 are also vulnerable. The issue was fixed in the specified versions and subsequent releases.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly reported exploits at the time of analysis. A bypass of the same-origin policy in the Cookies component could potentially allow attackers to leverage cross-origin cookie access, posing a risk to authentication and session integrity. The risk is heightened for users who interact with unsanctioned web content or rely on browser extensions that inject or modify page content. While no active exploits are known, the theoretical impact on confidentiality and integrity warrants remediation.

Generated by OpenCVE AI on August 21, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox to version 154, ESR 140.14, or ESR 153.1, or any later release.
  • Update Thunderbird to version 154, 140.14, or 153.1, or any later release.
  • If an upgrade cannot be performed immediately, consider using the cookie manager to delete potentially compromised cookies or enforce stricter SameSite/HttpOnly attributes via about:config settings to reduce exposure.

Generated by OpenCVE AI on August 21, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4750-1 firefox-esr security update
Debian DLA Debian DLA DLA-4754-1 thunderbird security update
Debian DSA Debian DSA DSA-6451-1 firefox-esr security update
Debian DSA Debian DSA DSA-6461-1 thunderbird security update
History

Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 19 Aug 2026 00:15:00 +0000


Tue, 18 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264
CWE-284

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-264
CWE-284
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Same-origin policy bypass in the Networking: Cookies component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T19:23:46.637Z

Reserved: 2026-08-17T11:58:28.953Z

Link: CVE-2026-74963

cve-icon Vulnrichment

Updated: 2026-08-18T19:23:37.470Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:33.560

Modified: 2026-08-19T01:00:22.793

Link: CVE-2026-74963

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T12:23:32Z

Links: CVE-2026-74963 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:30:04Z

Weaknesses