Mozilla Revokes Firefox Signing Key After GitHub Exposure of Subkey
Key Takeaways Mozilla has revoked a GPG signing subkey after its unencrypted copy was inadvertently committed to a private GitHub repository. The exposed key was used for signing specific Firefox and...
Key Takeaways
- Mozilla has revoked a GPG signing subkey after its unencrypted copy was inadvertently committed to a private GitHub repository.
- The exposed key was used for signing specific Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files.
- While Mozilla found no evidence of unauthorized access or misuse, the revocation is a precautionary measure to maintain software supply-chain integrity.
- Most users will not be affected, but those who manually validate GPG signatures or use certain Linux distributions (e.g., older Fedora, RHEL, Rocky Linux) must take manual steps to update their signing keys.
Mozilla Revokes Firefox Signing Key After Internal GitHub Exposure
Mozilla has taken swift action to rotate a GPG signing subkey following its accidental exposure within a private GitHub repository. The unencrypted subkey, integral to signing specific release artifacts for Firefox and Thunderbird, was inadvertently committed, prompting a precautionary revocation by the organization.
Table Of Content
Details of the Incident
The compromised subkey was specifically utilized to sign Linux tarballs, RPM packages, and associated checksum files for Firefox and Thunderbird releases. Mozilla has confirmed that the incident’s scope was limited, affecting only a subset of users, and critically, there is no evidence to suggest that unauthorized parties accessed or copied the key during its presence in the repository.
An internal review of audit logs revealed that access to the private GitHub repository was strictly confined to a small, authorized internal Mozilla team. Furthermore, every individual with repository access already possessed legitimate authorization to access the signing key through established, secure channels. Despite the absence of malicious access, Mozilla proactively revoked the compromised signing key to mitigate any potential future risks and has implemented enhanced safeguards to prevent similar key-handling errors.
Importance of GPG Signing Keys
GPG signing keys are a foundational component of software supply-chain security. They enable users, package managers, and system administrators to verify the authenticity and integrity of downloaded software, ensuring that Firefox and Thunderbird files originate from Mozilla and have not been tampered with post-release. A leaked private signing subkey, even without evidence of misuse, theoretically poses a risk by allowing an attacker to create seemingly legitimate, yet malicious, software packages. The revocation effectively neutralizes this potential threat by invalidating the subkey’s ability to sign trusted future releases.
Impact on Users and Required Actions
The majority of Firefox and Thunderbird users are not required to take any immediate action. Standard browser installations and automatic update processes are designed to handle such key rotations seamlessly, without interruption.
Manual GPG Validation Users
Users who manually validate Mozilla release signatures with GPG must import the newly published signing key. They also need to import the revocation certificate for the previous key. Mozilla advises that releases signed with the revoked key may no longer validate after the revocation is imported, which is standard GPG behavior.
Firefox RPM Users
Firefox RPM users may need to take specific actions depending on their Linux distribution. Fedora 43 and newer systems are expected to automatically download the updated signing key during their next software update cycle. Users should verify that the displayed subkey fingerprint matches 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3 before accepting the import.
Conversely, older Fedora releases (Fedora 42 and earlier), as well as systems running RHEL, Rocky Linux, AlmaLinux, openSUSE, and SUSE, do not automatically replace the old key. Administrators on these affected systems may encounter package update failures, with messages indicating incorrect GPG keys, failed signature verification, or missing trusted keys. These users must first remove the outdated RPM signing key, then import Mozilla’s new replacement key, and finally refresh their package metadata.
Mozilla has identified the new primary GPG key fingerprint as 14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353. This new signing subkey is set to expire on 2028-08-05. The public key and the revocation for the old key are accessible via Firefox Nightly KEY files, keys.openpgp.org, and Mozilla’s officially published key material.
This incident underscores the persistent challenge of securing cryptographic material within software supply chains, emphasizing that even internal exposures within restricted environments necessitate prompt and decisive action to maintain trust and security.
What You Should Do
- Most Users: No immediate action is required. Your browser and operating system should handle the key rotation automatically.
- Users Manually Validating GPG Signatures: Import the new signing key and the revocation certificate for the old key from Mozilla’s official sources.
- Fedora 43+ RPM Users: Verify the new subkey fingerprint (
827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3) during your next update. - Older Fedora, RHEL, Rocky Linux, AlmaLinux, openSUSE, SUSE RPM Users: Manually remove the old RPM signing key, import the new Mozilla key (
14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353), and refresh your package metadata to avoid update failures. - Stay Informed: Regularly check official Mozilla security advisories for any further updates or instructions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.