ITSECURITYWHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardVulnerabilities › CVE-2026-74949
8.8High CVE-2026-74949 Mozilla

Privilege escalation due to use-after-free in the Graphics: Canvas2D component.

Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

What happened

Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Does it affect you

Not enough information

No products recorded, so this cannot be matched against anything.

What to do

  • Follow the vendor advisory for the fixed release and any interim mitigation.
    mozilla.org
  • Follow the vendor advisory for the fixed release and any interim mitigation.
    mozilla.org
  • Follow the vendor advisory for the fixed release and any interim mitigation.
    mozilla.org
  • Follow the vendor advisory for the fixed release and any interim mitigation.
    mozilla.org

Vendor's affected list

firefox
Everything below 140.14.0

Sources

A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.