Mozilla Foundation Security Advisory 2026-68
Security Vulnerabilities fixed in Firefox 153
- Announced
- July 21, 2026
- Impact
- high
- Products
- Firefox
- Fixed in
-
- Firefox 153
#CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component
- Reporter
- Tran Quac
- Impact
- high
References
#CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component
- Reporter
- Tomoya Nakanishi
- Impact
- high
References
#CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
- Reporter
- crixer
- Impact
- high
References
#CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component
- Reporter
- Oskar L
- Impact
- high
References
#CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component
- Reporter
- Nebula Security
- Impact
- high
References
#CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component
- Reporter
- stevej
- Impact
- high
References
#CVE-2026-16365: Privilege escalation in the DOM: Workers component
- Reporter
- Khanh Nguyen
- Impact
- high
References
#CVE-2026-16366: Privilege escalation in the DOM: Navigation component
- Reporter
- Khanh Nguyen
- Impact
- high
References
#CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
- Reporter
- fedek
- Impact
- high
References
#CVE-2026-16354: Information disclosure in the Graphics: ImageLib component
- Reporter
- satyamasd
- Impact
- high
References
#CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component
- Reporter
- Oskar L
- Impact
- high
References
#CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component
- Reporter
- Nebula Security
- Impact
- high
References
#CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component
- Reporter
- Oskar L
- Impact
- high
References
#CVE-2026-16357: Incorrect boundary conditions in the Graphics component
- Reporter
- 5up3rh3i
- Impact
- high
References
#CVE-2026-16370: Mitigation bypass in the DOM: Networking component
- Reporter
- tiebuchen
- Impact
- moderate
References
#CVE-2026-16371: Privilege escalation in the DOM: Navigation component
- Reporter
- stevej
- Impact
- moderate
References
#CVE-2026-16372: Privilege escalation in the DOM: Content Processes component
- Reporter
- Sajeeb Lohani
- Impact
- moderate
References
#CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android
- Reporter
- Satoki Tsuji
- Impact
- moderate
References
#CVE-2026-16374: Information disclosure in the Framework component in DevTools
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-16375: Site isolation issue in the Networking: HTTP component
- Reporter
- pakhunov.anton.n
- Impact
- moderate
References
#CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
- Reporter
- Mihalis Haatainen
- Impact
- moderate
References
#CVE-2026-16377: Mitigation bypass in the PDF Viewer component
- Reporter
- Nikola Kojic
- Impact
- moderate
References
#CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component
- Reporter
- Farhad Sajid Barbhuiya
- Impact
- moderate
References
#CVE-2026-16379: Privilege escalation in the DOM: Content Processes component
- Reporter
- Shu Takahashi
- Impact
- moderate
References
#CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
- Reporter
- Hcamael
- Impact
- moderate
References
#CVE-2026-16380: Mitigation bypass in the Networking component
- Reporter
- Rintaro Kawasugi
- Impact
- moderate
References
#CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component
- Reporter
- Rintaro Kawasugi
- Impact
- moderate
References
#CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-16383: Mitigation bypass in the DOM: Networking component
- Reporter
- Ibuki Sato and Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-16387: Site isolation issue in the Networking component
- Reporter
- Atsushi Sada
- Impact
- moderate
References
#CVE-2026-16388: Sandbox escape in the DOM: Networking component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
- Reporter
- Souma Ohsawa
- Impact
- moderate
References
#CVE-2026-16391: Information disclosure in the Storage: IndexedDB component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component
- Reporter
- Gary Kwong
- Impact
- moderate
References
#CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component
- Reporter
- Atsushi Sada
- Impact
- moderate
References
#CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component
- Reporter
- Jacolon Walker
- Impact
- moderate
References
#CVE-2026-16394: Mitigation bypass in the DOM: Security component
- Reporter
- Nithissh
- Impact
- moderate
References
#CVE-2026-16395: Integer overflow in the Audio/Video component
- Reporter
- stevej
- Impact
- moderate
References
#CVE-2026-16396: Privilege escalation in WebExtensions
- Reporter
- Quy Pham
- Impact
- moderate
References
#CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android
- Reporter
- Hafiizh
- Impact
- moderate
References
#CVE-2026-16398: Site isolation issue in the Graphics component
- Reporter
- stevej
- Impact
- moderate
References
#CVE-2026-16399: Site isolation issue in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-16400: Information disclosure in the DOM: Security component
- Reporter
- Rintaro Kawasugi
- Impact
- moderate
References
#CVE-2026-16401: Privilege escalation in the Data Loss Prevention component
- Reporter
- Brian Carpenter
- Impact
- moderate
References
#CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
- Reporter
- Kai Martin
- Impact
- moderate
References
#CVE-2026-16403: Spoofing issue in the Address Bar component
- Reporter
- Renwa
- Impact
- low
References
#CVE-2026-16404: Spoofing issue in Firefox for Android
- Reporter
- Khiem Tran
- Impact
- low
References
#CVE-2026-16405: Information disclosure in the Networking: WebSockets component
- Reporter
- Yaqoub Aldurayhim
- Impact
- low
References
#CVE-2026-16406: Mitigation bypass in the Networking component
- Reporter
- Rintaro Kawasugi
- Impact
- low
References
#CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component
- Reporter
- bug2own
- Impact
- low
References
#CVE-2026-16408: Integer overflow in the Audio/Video: Playback component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-16409: Invalid pointer in the Security: PSM component
- Reporter
- Artur Cygan
- Impact
- low
References
#CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component
- Reporter
- Amy Burnett of OpenAI
- Impact
- low
References
#CVE-2026-16411: Memory safety bugs fixed in Firefox 153
- Reporter
- C.M.Chang, Christian Holler, David Parks, Dennis Jackson, Gabriele Svelto, Hafiizh, Henrik Skupin, Jan de Mooij, Jens Stutte, Paul Theriault, Randell Jesup, Rob Wu, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
- Impact
- high
Description
Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
References
#CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
- Reporter
- Christian Holler, Frederik Braun, Justin Link, Simon Friedberger, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
- Impact
- high
Description
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
References
#CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
- Reporter
- Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla and the Mozilla Fuzzing Team
- Impact
- high
Description
Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.