Mozilla Revokes Firefox and Thunderbird Signing Key After Unencrypted Subkey Was Committed to GitHub

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Mozilla has rotated a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was accidentally committed to a private GitHub repository.

The exposed key was used to sign Linux tarballs, RPM packages, and checksum files. Mozilla said the incident did not affect most users, and there is no evidence that an unauthorized party accessed or copied the key. At the same time, it was stored in the repository.

The company reviewed available audit logs and found that access to the private GitHub repository was restricted to a small internal Mozilla group.

According to Mozilla, every person with repository access was already authorized to access the signing key through other approved channels.

However, Mozilla revoked the previous signing key as a precaution and introduced additional safeguards designed to prevent similar key-handling mistakes in the future.

GPG signing keys are a critical part of software supply-chain security. They allow users, package managers, and administrators to verify that downloaded Firefox and Thunderbird files were produced by Mozilla and were not modified after release.

Mozilla Revokes Firefox Signing Key

A leaked private signing subkey could theoretically allow an attacker to create malicious packages that appear legitimate. Although Mozilla found no evidence of misuse, revoking the exposed subkey removes its ability to sign future trusted releases.

Most Firefox and Thunderbird users do not need to take any action. Standard browser installations and updates are not expected to be disrupted by the rotation.

Users who manually validate Mozilla release signatures with GPG must import the newly published signing key and the revocation certificate for the earlier key.

Mozilla warned that releases signed with the revoked key may no longer validate after the revocation is imported, which is normal GPG behavior.

Firefox RPM users may need to act depending on their Linux distribution. Fedora 43 and later systems should automatically download the updated signing key during the next update.

Users must verify that the displayed subkey fingerprint matches 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3 before accepting the import.

Older Fedora releases, including Fedora 42 and earlier, as well as RHEL, Rocky Linux, AlmaLinux, openSUSE, and SUSE systems, cannot automatically replace the old key.

On affected systems, package updates may fail with messages stating that the installed GPG key is incorrect, that signature verification failed, or that no trusted key is available. Administrators must first remove the old RPM signing key, import Mozilla’s replacement key, and refresh package metadata.

Mozilla identified the new primary GPG key fingerprint as 14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353. The new signing subkey expires on 2028-08-05.

The public key and old-key revocation are available through Firefox Nightly KEY files, keys.openpgp.org, and Mozilla’s published key material.

The event highlights a recurring supply-chain security concern: private cryptographic material can create serious risk even when accidentally exposed only inside restricted repositories.

Mozilla’s response auditing access, revoking the old subkey, rotating credentials, and publishing distribution-specific remediation limits the potential impact while preserving trust in its signed software releases.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.