CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 154 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 154 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 153.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-75874
- CVE-2026-74934
- CVE-2026-74935
- CVE-2026-74936
- CVE-2026-74937
- CVE-2026-74938
- CVE-2026-74939
- CVE-2026-74940
- CVE-2026-74941
- CVE-2026-74942
- CVE-2026-74943
- CVE-2026-74944
- CVE-2026-74945
- CVE-2026-74946
- CVE-2026-74947
- CVE-2026-74948
- CVE-2026-74949
- CVE-2026-74950
- CVE-2026-74951
- CVE-2026-74952
- CVE-2026-74953
- CVE-2026-74954
- CVE-2026-74955
- CVE-2026-74956
- CVE-2026-74957
- CVE-2026-74958
- CVE-2026-74959
- CVE-2026-74960
- CVE-2026-74961
- CVE-2026-74962
- CVE-2026-74963
- CVE-2026-74964
- CVE-2026-74965
- CVE-2026-74966
- CVE-2026-74967
- CVE-2026-74968
- CVE-2026-74969
- CVE-2026-74970
- CVE-2026-74971
- CVE-2026-74972
- CVE-2026-74973
- CVE-2026-74974
- CVE-2026-74975
- CVE-2026-74976
- CVE-2026-74977
- CVE-2026-74978
- CVE-2026-74979
- CVE-2026-74980
- CVE-2026-74981
- CVE-2026-74982
- CVE-2026-74983
- CVE-2026-74984
- CVE-2026-74985
- CVE-2026-74986
- CVE-2026-74987
- CVE-2026-74988
- CVE-2026-74989
- CVE-2026-74990
Frequently Asked Questions
What should administrators do to remediate this issue?
Install Firefox 154 or Firefox ESR 153.1, which contain the fix. The provided data does not identify any workaround or mitigation for systems that cannot be updated immediately.
How can I determine whether my deployment needs the update?
Firefox versions earlier than 154 and Firefox ESR versions earlier than 153.1 should be treated as affected based on the stated fixed versions. The provided data does not specify configuration-dependent conditions or a method to detect exploitation.