External risk intelligence

Firefox and Thunderbird Add-ons Manager Mitigation Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-74979

The vulnerability affects the Add-ons Manager component within a web browser and email client. These are client-side desktop applications. Vulnerabilities in local browser components require user interaction and are not typically reachable or exposed as internet-facing services or gateways.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A mitigation bypass in the Add-ons Manager component of Mozilla products could allow attackers to bypass security controls. This issue has been addressed in recent updates to Firefox and Thunderbird. The main concern is confirming relevance and exposure to our specific deployed software.

  • Bypass security controls in browser add-ons.
  • Allows advanced persistent threats.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

This vulnerability allows an attacker to bypass security measures within the Add-ons Manager component. An unauthenticated attacker on the network could leverage this flaw to achieve high impact, potentially leading to code execution or significant data compromise.

  • No authentication or user interaction needed.
  • Exploits the Add-ons Manager component.
  • High impact mitigation bypass.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a mitigation bypass in the Add-ons Manager component could allow an attacker to bypass security restrictions. This may impact the integrity and availability of the application's functionality and data.

  • User-installed add-ons.
  • Malicious add-ons could be installed.
  • Application functionality and data integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this vulnerability affects the Add-ons Manager component in Firefox and Thunderbird, responsibility likely falls to end-user device management teams and potentially application owners for custom deployments, with security teams involved in oversight and coordination. The initial practical step is to inventory all Firefox and Thunderbird instances, assess their reachability and business criticality, identify accountable owners for each, and then prioritize remediation efforts based on risk.

  • Identify device and application owners.
  • Verify browser and client reachability and criticality.
  • Plan coordinated remediation with vendor.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Add-ons Manager in Firefox and Thunderbird?

The Add-ons Manager is a built-in component within Firefox and Thunderbird that allows users to discover, install, manage, and update browser extensions and themes. It acts as the central control panel for extending the functionality of these applications, ensuring that installed add-ons operate within the browser or email client's security architecture.

What does a mitigation bypass mean for CVE-2026-74979?

This vulnerability is categorized under CWE-284, which relates to improper access control. In the context of CVE-2026-74979, a mitigation bypass means the security checks normally enforced by the Add-ons Manager can be circumvented. This allows a process or malicious add-on to operate outside of its intended security boundaries, effectively ignoring restrictions that are designed to keep the application and your data safe.

Does this vulnerability trigger just by opening the browser?

The vulnerability involves the Add-ons Manager component. While it allows for a bypass of security controls, it is not triggered simply by launching the application. The flaw specifically relates to how the system handles add-on management and security restrictions, rather than a generic network-based trigger that would activate upon standard application startup.

Is my computer at risk according to Halo Surface Signal?

Halo Surface Signal indicates that this vulnerability is very unlikely to be an immediate risk because it affects client-side desktop applications like Firefox and Thunderbird. Unlike internet-facing servers or gateways, these components are local to the user's machine, meaning they are not typically exposed to direct, remote network attacks in a way that would make them easily reachable for exploitation.

How do I secure my systems against this CVE?

The primary response is to update your software to the versions where this issue was addressed: Firefox 154, Firefox ESR 153.1, Thunderbird 154, or Thunderbird 153.1. Start by inventorying all instances of these applications across your environment to identify which systems are running older versions, then coordinate with device owners to apply the latest updates provided by Mozilla to close this security gap.

References