"Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository," Mozilla noted.
Mozilla rotates the GPG signing subkey and revokes the exposed key
Mozilla said it moved to a new GPG signing subkey for signing specific Firefox and Thunderbird artifacts after discovering an unencrypted copy of the previous subkey in a private GitHub repository. Following that discovery, Mozilla revoked the key that had been used to sign Linux tarballs, RPM packages, and checksum files, and said it has taken measures to prevent similar issues going forward.
Audit findings: limited exposure and no evidence of unauthorized access
Mozilla reported that access to the private repository where the key was committed was limited to a small group within Mozilla. The company said that group's members "already had authorized access to the key through other means." Mozilla also stated that its review of available audit records "found no evidence that the key was accessed by an unauthorized party while it was present in the repository."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat Linux RPM users, Thunderbird users, and manual GPG verifiers must do
Mozilla said most users will not need to take any action after the GPG key rotation. It specified two groups that must act: users who manually verify GPG signatures, and Linux users who install Firefox using RPM packages.
- Manual verifiers: Mozilla said users who verify GPG signatures "must import the new signing key and the revocation for the old key."
- RPM-based Linux users: The organization warned that users who install Firefox via RPM packages may need to manually update their systems to continue receiving the latest Firefox updates. Mozilla shared detailed, distribution-specific instructions covering Fedora 43 and later, Fedora 42 and older, RHEL/Rocky/Almalinux, and openSUSE/SUSE-based distributions.
- Thunderbird note: Because Thunderbird does not provide official RPM packages, Mozilla said no RPM-specific action is required for Thunderbird users.
Where to get the new key, the revocation, and the key lifetime
Mozilla published the new public key and the revocation for the previous key through the latest Firefox Nightly KEY files and on keys.openpgp.org. The company also disclosed the new signing subkey's expiry date: August 5, 2028.
Revoked artifacts and the operational reach of the change
Mozilla identified the specific artifacts affected by the revoked key: Linux tarballs, RPM packages, and checksum files. By revoking the exposed subkey and issuing a replacement, Mozilla limited the scope of the rotation to those artifacts; the company did not report any evidence that the exposed key was used maliciously while present in the repository.
Mozilla's public account frames this as a contained operational incident: a subkey was accidentally committed to a private repository, access was narrow, and audit records show no signs of unauthorized copying. The organization replaced and revoked the key, published the new key and the revocation, and supplied distribution-specific remediation steps for RPM-based Linux users and instructions for anyone who manually verifies signatures. For administrators and users reliant on manual verification or on RPM installs, following Mozilla's published steps will be the immediate action required to remain on current, signed releases.
Source: BleepingComputer — Mozilla updates GPG key for signing Firefox, Thunderbird releases after exposure




