Mozilla Foundation Security Advisory 2026-77

Security Vulnerabilities fixed in Firefox ESR 153.1

Announced
August 18, 2026
Impact
high
Products
Firefox ESR
Fixed in
  • Firefox ESR 153.1

#CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component

Reporter
satyamasd
Impact
high
References

#CVE-2026-74935: Privilege escalation in the DOM: Networking component

Reporter
Yaqoub Aldurayhim
Impact
high
References

#CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component

Reporter
Amy Burnett of OpenAI
Impact
high
References

#CVE-2026-74937: Use-after-free in the JavaScript: GC component

Reporter
Amy Burnett of OpenAI
Impact
high
References

#CVE-2026-74938: Mitigation bypass in the JavaScript: GC component

Reporter
Amy Burnett of OpenAI
Impact
high
References

#CVE-2026-74939: Privilege escalation in the DOM: Navigation component

Reporter
choeseyeong
Impact
high
References

#CVE-2026-74940: Use-after-free in the Graphics: Text component

Reporter
kiyong
Impact
high
References

#CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component

Reporter
Jacolon Walker
Impact
high
References

#CVE-2026-74942: Privilege escalation in the Remote Settings Client component

Reporter
Gal Ankonina
Impact
high
References

#CVE-2026-74943: Use-after-free in the Graphics: ImageLib component

Reporter
Abdulaziz Alasaiqah
Impact
high
References

#CVE-2026-74944: Use-after-free in the DOM: Core & HTML component

Reporter
Amy Burnett of OpenAI
Impact
high
References

#CVE-2026-74945: Information disclosure in the Graphics: Text component

Reporter
Abdulaziz Alasaiqah
Impact
high
References

#CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
locust1b
Impact
high
References

#CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component

Reporter
navapon
Impact
high
References

#CVE-2026-74948: Information disclosure in the Graphics component

Reporter
Yaqoub Aldurayhim
Impact
high
References

#CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component

Reporter
r00tdaddy
Impact
high
References

#CVE-2026-74950: Privilege escalation in the Downloads API component

Reporter
Frederik Braun
Impact
moderate
References

#CVE-2026-74953: Privilege escalation in the Networking: Cookies component

Reporter
Satoki Tsuji
Impact
moderate
References

#CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component

Reporter
Tomoya Nakanishi
Impact
moderate
References

#CVE-2026-74955: Privilege escalation in the Request Handling component

Reporter
jmwebdevelopement
Impact
moderate
References

#CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component

Reporter
pakhunov.anton.n
Impact
moderate
References

#CVE-2026-74957: Mitigation bypass in the Safe Browsing component

Reporter
Tomoya Nakanishi
Impact
moderate
References

#CVE-2026-74958: Information disclosure in the WebRTC component

Reporter
Tomoya Nakanishi
Impact
moderate
References

#CVE-2026-74959: Mitigation bypass in the Storage: Cache API component

Reporter
David Bors at Snyk Security Labs
Impact
moderate
References

#CVE-2026-74960: Site isolation issue in the WebExtensions component

Reporter
Khanh Nguyen
Impact
moderate
References

#CVE-2026-74961: Side-channel in the Web Audio component

Reporter
Rintaro Kawasugi
Impact
moderate
References

#CVE-2026-74962: Site isolation issue in the Networking: Cookies component

Reporter
Yaqoub Aldurayhim
Impact
moderate
References

#CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component

Reporter
5up3rh3i
Impact
moderate
References

#CVE-2026-74964: Integer overflow in the Graphics component

Reporter
5up3rh3i
Impact
moderate
References

#CVE-2026-74965: Privilege escalation in the Shell Integration component

Reporter
Khanh Nguyen
Impact
moderate
References

#CVE-2026-74966: Information disclosure in the Form Autofill component

Reporter
The Mozilla Fuzzing Team
Impact
moderate
References

#CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component

Reporter
The Mozilla Fuzzing Team
Impact
moderate
References

#CVE-2026-74968: Site isolation issue in the Graphics: WebRender component

Reporter
kiyong
Impact
moderate
References

#CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component

Reporter
Hyeonjun Ahn
Impact
moderate
References

#CVE-2026-74970: Site isolation issue in the Graphics component

Reporter
Abdulaziz Alasaiqah
Impact
moderate
References

#CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component

Reporter
avlidienbrunn
Impact
moderate
References

#CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component

Reporter
Kagami Rosylight
Impact
moderate
References

#CVE-2026-74973: Race condition, use-after-free in the Graphics component

Reporter
r00tdaddy
Impact
moderate
References

#CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component

Reporter
The Mozilla Fuzzing Team
Impact
moderate
References

#CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component

Reporter
anbu
Impact
low
References

#CVE-2026-74977: Integer overflow in the Graphics component

Reporter
Vladimir Meier
Impact
low
References

#CVE-2026-74978: Clickjacking issue in the Widget component

Reporter
hafidzaulia28
Impact
low
References

#CVE-2026-74979: Mitigation bypass in the Add-ons Manager component

Reporter
Tomoya Nakanishi
Impact
low
References

#CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component

Reporter
5up3rh3i
Impact
low
References

#CVE-2026-74982: Denial-of-service in the Widget component

Reporter
Riski Muhammad Ivan
Impact
low
References

#CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component

Reporter
5up3rh3i
Impact
low
References

#CVE-2026-74984: Race condition in the JavaScript Engine component

Reporter
Amy Burnett of OpenAI
Impact
low
References

#CVE-2026-74985: Privilege escalation in the Enterprise Policies component

Reporter
The Mozilla Fuzzing Team
Impact
low
References

#CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component

Reporter
5up3rh3i
Impact
low
References

#CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Reporter
Nicolas Silva, Tom Ritter and the Mozilla Fuzzing Team
Impact
high
Description

Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.

References

#CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154

Reporter
Gabriele Svelto, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
Impact
high
Description

Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.

References

#CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Reporter
Christian Holler, Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
Impact
high
Description

Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.

References