• 2 min read
Mozilla revokes Firefox signing key after GitHub exposure
Mozilla revoked a Firefox and Thunderbird signing key after an unencrypted copy was accidentally committed to a private GitHub repository.

Source: The Register
Mozilla has revoked and replaced a GPG private subkey used to sign Firefox and Thunderbird releases after an unencrypted copy was accidentally committed to a private GitHub repository. [The Register](https://www.theregister.com/security/2026/08/11/mozilla-revokes-firefox-signing-key-after-unencrypted-copy-lands-in-github/5285908) reports that the repository was accessible to a small group of Mozilla employees, all of whom were already authorized to access the key through other channels.
The affected key signed Linux tarballs, RPM packages, and checksum files. Mozilla said its audit-log review found “no evidence that the key was accessed by an unauthorized party while it was present in the repository.” The company has added safeguards to prevent a repeat, but has not explained how the key reached GitHub or how long it remained there.
Most users will not need to do anything. People who manually verify Mozilla’s GPG signatures must import the replacement key and the revocation for the old one. Users of Firefox’s RPM repository face additional steps:
- Fedora 43 and later: DNF should download the updated key with the next Firefox update, though users will need to approve the import.
- Fedora 42 and earlier, RHEL, Rocky Linux, AlmaLinux, openSUSE, and SUSE: Users must remove the old key and manually import its replacement.
After the revocation is imported, standard signature verification will reject older releases signed with the revoked subkey. Thunderbird users do not face the RPM-specific issue because Mozilla does not provide official RPM packages for the email client.
Mozilla did not answer The Register’s questions about how the key was exposed, how long it was stored in the repository, or whether the audit logs covered the entire exposure period.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.


