Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74974— Same-origin policy bypass in the Graphics: ImageLib component

AI Predicted 6.4 Difficulty: Moderate

Possible ATT&CK Techniques 1AI

T1055 · Process Injection
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-74974

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Same-origin policy bypass in the Graphics: ImageLib component
Source: CVE Program / CVE List V5
Vulnerability Description
Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
MozillaFirefox 115.39 ~ 115.* -

II. Public POCs for CVE-2026-74974

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74974

登录查看更多情报信息。

Vendor Advisories for CVE-2026-74974 (4)

Same Patch Batch · Mozilla · 2026-08-18 · 58 CVEs total

CVE-2026-74963Same-origin policy bypass in the Networking: Cookies component
CVE-2026-74942Privilege escalation in the Remote Settings Client component
CVE-2026-74939Privilege escalation in the DOM: Navigation component
CVE-2026-74940Use-after-free in the Graphics: Text component
CVE-2026-74941Privilege escalation in the Graphics: CanvasWebGL component
CVE-2026-74935Privilege escalation in the DOM: Networking component
CVE-2026-74959Mitigation bypass in the Storage: Cache API component
CVE-2026-74953Privilege escalation in the Networking: Cookies component
CVE-2026-74964Integer overflow in the Graphics component
CVE-2026-74962Site isolation issue in the Networking: Cookies component
CVE-2026-74957Mitigation bypass in the Safe Browsing component
CVE-2026-74960Site isolation issue in the WebExtensions component
CVE-2026-74967Same-origin policy bypass in the Audio/Video: Playback component
CVE-2026-74971Information disclosure in the DOM: UI Events & Focus Handling component
CVE-2026-74969Use-after-free in the Layout: Text and Fonts component
CVE-2026-74965Privilege escalation in the Shell Integration component
CVE-2026-74973Race condition, use-after-free in the Graphics component
CVE-2026-74976JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-74972Information disclosure in the DOM: Push Subscriptions component
CVE-2026-74983Mitigation bypass in the Data Loss Prevention component

Showing top 20 of 58 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-74974

No comments yet


Leave a comment