Mozilla Foundation Security Advisory 2026-77
Security Vulnerabilities fixed in Firefox ESR 153.1
- Announced
- August 18, 2026
- Impact
- high
- Products
- Firefox ESR
- Fixed in
-
- Firefox ESR 153.1
#CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
- Reporter
- satyamasd
- Impact
- high
References
#CVE-2026-74935: Privilege escalation in the DOM: Networking component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74937: Use-after-free in the JavaScript: GC component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74938: Mitigation bypass in the JavaScript: GC component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74939: Privilege escalation in the DOM: Navigation component
- Reporter
- choeseyeong
- Impact
- high
References
#CVE-2026-74940: Use-after-free in the Graphics: Text component
- Reporter
- kiyong
- Impact
- high
References
#CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component
- Reporter
- Jacolon Walker
- Impact
- high
References
#CVE-2026-74942: Privilege escalation in the Remote Settings Client component
- Reporter
- Gal Ankonina
- Impact
- high
References
#CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
- Reporter
- Abdulaziz Alasaiqah
- Impact
- high
References
#CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74945: Information disclosure in the Graphics: Text component
- Reporter
- Abdulaziz Alasaiqah
- Impact
- high
References
#CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- locust1b
- Impact
- high
References
#CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component
- Reporter
- navapon
- Impact
- high
References
#CVE-2026-74948: Information disclosure in the Graphics component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component
- Reporter
- r00tdaddy
- Impact
- high
References
#CVE-2026-74950: Privilege escalation in the Downloads API component
- Reporter
- Frederik Braun
- Impact
- moderate
References
#CVE-2026-74953: Privilege escalation in the Networking: Cookies component
- Reporter
- Satoki Tsuji
- Impact
- moderate
References
#CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-74955: Privilege escalation in the Request Handling component
- Reporter
- jmwebdevelopement
- Impact
- moderate
References
#CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component
- Reporter
- pakhunov.anton.n
- Impact
- moderate
References
#CVE-2026-74957: Mitigation bypass in the Safe Browsing component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-74958: Information disclosure in the WebRTC component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
- Reporter
- David Bors at Snyk Security Labs
- Impact
- moderate
References
#CVE-2026-74960: Site isolation issue in the WebExtensions component
- Reporter
- Khanh Nguyen
- Impact
- moderate
References
#CVE-2026-74961: Side-channel in the Web Audio component
- Reporter
- Rintaro Kawasugi
- Impact
- moderate
References
#CVE-2026-74962: Site isolation issue in the Networking: Cookies component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-74964: Integer overflow in the Graphics component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-74965: Privilege escalation in the Shell Integration component
- Reporter
- Khanh Nguyen
- Impact
- moderate
References
#CVE-2026-74966: Information disclosure in the Form Autofill component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- moderate
References
#CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- moderate
References
#CVE-2026-74968: Site isolation issue in the Graphics: WebRender component
- Reporter
- kiyong
- Impact
- moderate
References
#CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
- Reporter
- Hyeonjun Ahn
- Impact
- moderate
References
#CVE-2026-74970: Site isolation issue in the Graphics component
- Reporter
- Abdulaziz Alasaiqah
- Impact
- moderate
References
#CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component
- Reporter
- avlidienbrunn
- Impact
- moderate
References
#CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component
- Reporter
- Kagami Rosylight
- Impact
- moderate
References
#CVE-2026-74973: Race condition, use-after-free in the Graphics component
- Reporter
- r00tdaddy
- Impact
- moderate
References
#CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- moderate
References
#CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
- Reporter
- anbu
- Impact
- low
References
#CVE-2026-74977: Integer overflow in the Graphics component
- Reporter
- Vladimir Meier
- Impact
- low
References
#CVE-2026-74978: Clickjacking issue in the Widget component
- Reporter
- hafidzaulia28
- Impact
- low
References
#CVE-2026-74979: Mitigation bypass in the Add-ons Manager component
- Reporter
- Tomoya Nakanishi
- Impact
- low
References
#CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-74982: Denial-of-service in the Widget component
- Reporter
- Riski Muhammad Ivan
- Impact
- low
References
#CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-74984: Race condition in the JavaScript Engine component
- Reporter
- Amy Burnett of OpenAI
- Impact
- low
References
#CVE-2026-74985: Privilege escalation in the Enterprise Policies component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- low
References
#CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
- Reporter
- Nicolas Silva, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154
- Reporter
- Gabriele Svelto, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
- Reporter
- Christian Holler, Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.