Mozilla has rotated the GPG signing key used for certain Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository.

The company said the exposure created a potential risk of a software supply chain attack, where attackers could theoretically use the compromised key to distribute malicious installers that appear to have been legitimately signed by Mozilla. However, Mozilla said the risk is low because access to the private GitHub repository was restricted to a small group of employees.

Mozilla also said it has found no evidence that the exposed key was accessed by anyone who was not authorized to use it. The organization reviewed available audit records and found no indication of unauthorized access while the key was stored in the repository.

The affected signing subkey was used for certain Firefox and Thunderbird release files, including Linux tarballs, RPM packages, and checksum files. After discovering the issue, Mozilla revoked the old key and moved to a new GPG signing subkey.

“Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts,” Mozilla said in a security update, explaining that the previous subkey had been accidentally committed in an unencrypted form.

For most Firefox and Thunderbird users, no action is required. However, users who manually verify GPG signatures will need to import Mozilla’s new signing key and the revocation information for the old key.

READ
Google Confirms Blogger Bug Behind Mass Malware False Positives, Restoration Underway

Some Linux users who install Firefox through RPM packages may also need to manually update their systems. Mozilla has published specific instructions for users running Fedora 43 and later, Fedora 42 and older versions, RHEL, Rocky Linux, AlmaLinux, and openSUSE or SUSE-based distributions.

Thunderbird users do not need to take any RPM-specific action because Mozilla does not provide official RPM packages for Thunderbird.

Mozilla has also taken additional measures to prevent similar incidents from happening again. The new signing subkey is set to expire on August 5, 2028, while the new public key and revocation information for the previous key are available through the latest Firefox Nightly KEY files and keys.openpgp.org.

Although Mozilla has not found evidence that the exposed key was misused, rotating the credential helps remove the potential risk associated with the accidental exposure. The incident also highlights how carefully software signing keys need to be protected because attackers who obtain such keys could potentially use them to make malicious software appear authentic.


Buy ExpressVPN with PayPal or Credit Card

Advertisement