Sceawere

Vulnerability Detail

CVE-2026-74953UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Firefox Networking Cookies Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
5h ago
Vendor
Mozilla
Product
Firefox
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-18T13:17:32.230Z",
  "pubdate": "2026-08-18T13:17:32.230Z",
  "executiveSummary": "A privilege escalation vulnerability has been identified within the Networking: Cookies component of Mozilla Firefox. This security flaw introduces significant risk by potentially allowing unauthorized elevation of privileges within the context of the affected application. The vulnerability impacts Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.\nThe risk implications of this vulnerability include the potential compromise of browser security boundaries, allowing malicious entities to manipulate cookie data or execute unauthorized operations that exceed their intended privilege level. While specific attacker capabilities and complex exploitation requirements are constrained by the browser sandbox architecture, successful exploitation could lead to unauthorized access to sensitive session data or localized privilege escalation.\nOrganizations and end-users utilizing the affected software versions face exposure to potential cookie-based manipulation attacks. Immediate remediation through the application of official vendor patches is critical to restoring security posture and preventing potential exploitation vectors targeting the networking subsystem.",
  "technicalDetails": "The vulnerability resides within the Networking: Cookies component of the Mozilla Firefox architecture, specifically affecting how cookie state, parsing, or boundary enforcement is handled. The root cause stems from improper input validation, state management, or insufficient privilege checks during cookie processing operations within the networking stack.\nAffected products and versions comprise Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. The vulnerable component processes incoming HTTP state management headers and internal cookie storage requests. When interacting with maliciously crafted network payloads or interacting with specific script contexts, the flaw can be triggered to bypass security controls governing cookie access and modification.\nThe step-by-step attack flow typically involves an adversary delivering a specially crafted HTTP response or utilizing malicious content capable of interacting with the browser's networking and cookie storage subsystems. Due to the flaw in the Networking: Cookies component, the browser fails to correctly enforce isolation or permission checks. This permits unauthorized modification or access to sensitive cookie attributes, subverting the intended security boundaries.\nAuthentication and privilege requirements depend on the specific entry vector, but the vulnerability fundamentally impacts the internal privilege model of the browser's network process. Post-exploitation impact includes unauthorized persistence, session hijacking via compromised cookies, or further escalation within the application context depending on the integration of the cookie subsystem with other browser internals. Network exposure is inherent to any web-facing browser processing external HTTP traffic."
}
CVE-2026-74953: Firefox Networking Cookies Privilege Escalation (HIGH Severity, CVSS: 8.8) - Sceawere