Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4351 articles · 196743 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-74961PATCHED
mozilla · firefox

Side-channel in the Web Audio component

Description

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected Products

VendorProductVersions
mozillafirefox—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mozillathunderbirdcert_advisory90%
mozillafirefoxcert_advisory90%
mozillafirefox esrcert_advisory90%

References

  • https://bugzilla.mozilla.org/show_bug.cgi?id=2050380
  • https://www.mozilla.org/security/advisories/mfsa2026-74/
  • https://www.mozilla.org/security/advisories/mfsa2026-77/
  • https://www.mozilla.org/security/advisories/mfsa2026-78/
  • https://www.mozilla.org/security/advisories/mfsa2026-80/

Related News (3 articles)

Tier B
BSI Advisories5d ago
[NEU] [hoch] Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR6d ago
Multiples vulnérabilités dans les produits Mozilla (19 août 2026)
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-74961 | Mozilla Firefox prior 153.1/154 Web Audio integrity check
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
153.1154
PublishedAug 18, 2026
Trending Score32
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-74989EXP
Internally found bugs fixed in Firefox 154
Trending: 34
CRITICALCVE-2026-74979
Mitigation bypass in the Add-ons Manager component
Trending: 32
CRITICALCVE-2026-74940
Use-after-free in the Graphics: Text component
Trending: 32
CRITICALCVE-2026-74938
Mitigation bypass in the JavaScript: GC component
Trending: 32
CRITICALCVE-2026-74956
Same-origin policy bypass in the DOM: Service Workers component
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 18, 2026
Discovered by ZDM
Aug 18, 2026
Patch Available
Aug 20, 2026