CVE-2026-74972

Published: Ago 18, 2026 Last Modified: Ago 18, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.

https://bugzilla.mozilla.org/show_bug.cgi?id=2059053
https://www.mozilla.org/security/advisories/mfsa2026-74/
https://www.mozilla.org/security/advisories/mfsa2026-76/
https://www.mozilla.org/security/advisories/mfsa2026-77/