All incidents

Mozilla revokes Firefox GPG key after accidental GitHub exposure

incidentopenAug 11, 2026 — Aug 15, 2026
Mozilla revokes Firefox GPG key after accidental GitHub exposure

MOZILLA has revoked the GPG signing subkey used for Firefox and Thunderbird on Linux after the key was accidentally committed to a private GitHub repository. The discovery prompted the organisation to rotate the key and issue a new fingerprint that will be valid until August 2028. Users who rely on signature verification must now replace the old key with the new one to continue validating authentic releases. Mozilla announced the change on its security blog.

According to a report by SecurityOnline, the exposed subkey had been part of the signing infrastructure for several months before the commit was made, though an audit confirmed that no unauthorized party accessed the material. The key was stored in a private repository with limited visibility, but the possibility of a supply chain attack led Mozilla to treat the incident as a security event. The new subkey carries a different fingerprint and is intended for use with both the browser and the email client on Linux distributions. SecurityOnline details the rotation process and notes that the old key has been marked as revoked in the keyring.

The original key, had it been compromised, could have allowed attackers to create valid signatures for malicious updates, thereby bypassing the trust model that protects users from tampered binaries. Although the exposure was limited to a private fork, Mozilla opted for caution and revoked the subkey to eliminate any chance of abuse. No related CVE identifiers have been assigned to the incident, reflecting its nature as a procedural rather than a vulnerability‑based issue. The organisation said it has implemented additional safeguards to prevent similar commits in the future.

No threat actors have been linked to the leak, and there is no evidence that the key was used to sign harmful files before the revocation. SecurityWeek highlighted that the decision to issue a new key was taken as a precautionary measure, consistent with Mozilla’s commitment to supply chain integrity. The incident highlights the importance of monitoring internal repositories for accidental secrets, even when they are not publicly accessible. SecurityWeek covers the precautionary stance taken by the vendor.

Administrators and end users who verify GPG signatures manually should fetch the updated subkey from Mozilla’s key server and add it to their trusted keyring, then remove the old fingerprint to avoid confusion. Those who install Firefox or Thunderbird via RPM packages on distributions such as Fedora or Red Hat Enterprise Linux need to refresh the package signing key using the distribution’s key management tool, ensuring that the new key is imported before the next update.

Mozilla’s blog provides step‑by‑step commands for both approaches, including the exact fingerprint to verify. Following these steps will restore the ability to confirm that incoming updates are genuine and have not been altered.

Organisations that manage internal mirrors of Mozilla binaries should also update their verification scripts to reference the new subkey, and monitor logs for any signature failures that could indicate a problem with the key rotation. Mozilla recommends that users keep an eye on its security advisories for any further changes to the signing infrastructure. By maintaining an up‑to‑date keyring and applying the provided guidance, the risk of accepting a tampered release remains minimal.

Intelligence briefing updated Aug 15, 2026

Root sourceblog.mozilla.org
Timeline Coverage

Swipe to explore timeline