Mozilla has taken swift action to mitigate a potential security risk after discovering that its GPG signing key for Firefox and Thunderbird releases had been accidentally exposed on GitHub. The incident, which occurred due to an unencrypted copy of the previous subkey being inadvertently committed to a private repository, has prompted the organization to update the signing key used to sign certain artifacts, including Linux tarballs, RPM packages, and checksum files.
The risk of a supply chain attack is considered low by Mozilla, as only a limited number of individuals had access to the GitHub repository. Moreover, an internal review found no evidence that the exposed key was accessed by unauthorized parties while it was present in the repository. Nevertheless, to be on the safe side, Mozilla has taken measures to prevent similar issues in the future and has provided detailed instructions for users who need to update their systems.
The affected users are primarily those who manually verify GPG signatures or install Firefox using RPM packages on Linux distributions such as Fedora and openSUSE/SUSE-based systems. While most users won’t have to take any action, Mozilla has emphasized the importance of updating to the new signing key and revoking the old one to ensure continued security.
It’s worth noting that the exposure of a GPG signing key can potentially allow threat actors to distribute malicious installers signed with the compromised key. This highlights the importance of secure development practices and regular auditing to prevent such incidents from occurring in the first place.
In this particular case, Mozilla has taken proactive steps to address the issue, updating the signing subkey used for certain artifacts and providing clear instructions for affected users. This demonstrates a commitment to ensuring the security of its software releases and protecting its users’ trust.
To protect yourself from potential supply chain attacks, it’s essential to stay informed about any updates or changes to your software and operating system. If you manually verify GPG signatures or install software using RPM packages, be sure to check for any necessary updates and follow Mozilla’s instructions carefully. By staying vigilant and taking proactive measures, you can minimize the risk of falling victim to a supply chain attack.
Source: Bleeping Computer — 2026-08-11