📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

Firefox 153.0.3

Latest tracked version 153.0.3. Release status, tracked CVEs, and automated cross-platform patching for Firefox.

PlatformLatest versionCVEs trackedLast checked
Linux153.0.302026-08-10
Mac153.0.302026-08-10
Windows153.0.327722026-08-10

Known vulnerabilities (CVEs) in Firefox

Lavawall tracks 2772 published CVEs affecting Firefox, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2026-93092026-06-01 13:16:34MEDIUM (5)Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2.NETWORK
CVE-2026-93082026-06-01 13:16:34MEDIUM (5)Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.NETWORK
CVE-2026-90782026-05-25 15:16:23MEDIUM (5)Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portions of the displayed domain, causing attacker-controlled sites to appear as trusted origins. This vulnerability was fixed in Firefox for iOS 151.1.NETWORK
CVE-2026-89752026-05-19 14:16:54HIGH (9)Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89742026-05-19 14:16:54HIGH (9)Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89732026-05-19 14:16:54HIGH (9)Memory safety bugs present in Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89722026-05-19 14:16:54HIGH (9)Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89712026-05-19 14:16:54MEDIUM (7)Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89702026-05-19 14:16:54HIGH (9)Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89692026-05-19 14:16:53HIGH (8)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89682026-05-19 14:16:53HIGH (8)Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89672026-05-19 14:16:53HIGH (8)Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89662026-05-19 14:16:53HIGH (8)Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89652026-05-19 14:16:53HIGH (8)Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89642026-05-19 14:16:53HIGH (8)Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89632026-05-19 14:16:53HIGH (8)Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89622026-05-19 14:16:53HIGH (8)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89612026-05-19 14:16:52MEDIUM (7)Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89602026-05-19 14:16:52HIGH (8)Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89592026-05-19 14:16:52CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89582026-05-19 14:16:52HIGH (9)Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89572026-05-19 14:16:52HIGH (9)Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89562026-05-19 14:16:52CRITICAL (10)Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89552026-05-19 14:16:52HIGH (9)Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89542026-05-19 14:16:52HIGH (8)Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89532026-05-19 14:16:52CRITICAL (10)Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89522026-05-19 14:16:51HIGH (9)Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89512026-05-19 14:16:51MEDIUM (7)Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151.NETWORK
CVE-2026-89502026-05-19 14:16:51CRITICAL (9)Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89492026-05-19 14:16:51HIGH (8)Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89482026-05-19 14:16:51CRITICAL (9)Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.NETWORK
CVE-2026-89472026-05-19 14:16:51HIGH (7)Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89462026-05-19 14:16:51HIGH (8)Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.NETWORK
CVE-2026-89452026-05-19 14:16:51HIGH (8)Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.NETWORK
CVE-2026-87062026-05-19 16:16:23MEDIUM (7)Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-in user's cookies. This vulnerability was fixed in Firefox for iOS 151.0.ADJACENT_NETWORK
CVE-2026-84012026-05-12 15:16:20CRITICAL (10)Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3.NETWORK
CVE-2026-83912026-05-12 14:17:12MEDIUM (5)Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3.NETWORK
CVE-2026-83902026-05-12 14:17:12HIGH (7)Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.NETWORK
CVE-2026-83892026-05-12 14:17:12HIGH (9)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.NETWORK
CVE-2026-83882026-05-12 14:17:12MEDIUM (7)Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.NETWORK
CVE-2026-80942026-05-07 13:16:14CRITICAL (10)Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.NETWORK
CVE-2026-80932026-05-07 13:16:14HIGH (8)Memory safety bugs present in Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2 and Thunderbird 150.0.2.NETWORK
CVE-2026-80922026-05-07 13:16:14HIGH (8)Memory safety bugs present in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.NETWORK
CVE-2026-80912026-05-07 13:16:14CRITICAL (10)Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.NETWORK
CVE-2026-80902026-05-07 13:16:14HIGH (7)Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.NETWORK
CVE-2026-73242026-04-28 15:16:38HIGH (7)Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.NETWORK
CVE-2026-73232026-04-28 15:16:38HIGH (7)Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.NETWORK
CVE-2026-73222026-04-28 15:16:38HIGH (7)Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.NETWORK
CVE-2026-73212026-04-28 15:16:38CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.NETWORK
CVE-2026-73202026-04-28 15:16:37HIGH (8)Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.NETWORK
CVE-2026-67862026-04-26 19:53:40HIGH (8)Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67852026-04-26 19:53:39HIGH (8)Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67842026-04-21 13:16:24HIGH (8)Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67832026-04-21 13:16:24MEDIUM (5)Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67822026-04-21 13:16:24HIGH (8)Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67812026-04-21 13:16:24HIGH (8)Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67802026-04-21 13:16:24HIGH (8)Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67792026-04-21 13:16:24MEDIUM (5)Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67782026-04-21 13:16:24MEDIUM (5)Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67772026-04-21 13:16:23MEDIUM (5)Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67762026-04-21 13:16:23HIGH (8)Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.LOCAL
CVE-2026-67752026-04-21 13:16:23MEDIUM (5)Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67742026-04-21 13:16:23MEDIUM (5)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67732026-04-21 13:16:23HIGH (8)Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67722026-04-21 13:16:23HIGH (8)Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67712026-04-21 13:16:23CRITICAL (10)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67702026-04-21 13:16:23MEDIUM (7)Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67692026-04-21 13:16:23HIGH (9)Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67682026-04-21 13:16:23CRITICAL (10)Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67672026-04-21 13:16:23MEDIUM (5)Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67662026-04-21 13:16:22HIGH (8)Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67652026-04-21 13:16:22MEDIUM (5)Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67642026-04-21 13:16:22MEDIUM (7)Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67632026-04-21 13:16:22MEDIUM (7)Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67622026-04-21 13:16:22MEDIUM (6)Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67612026-04-21 13:16:22HIGH (9)Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67602026-04-21 13:16:22CRITICAL (10)Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67592026-04-21 13:16:22HIGH (8)Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67582026-04-21 13:16:22HIGH (8)Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67572026-04-21 13:16:22MEDIUM (6)Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67562026-04-21 13:16:22HIGH (8)Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.NETWORK
CVE-2026-67552026-04-21 13:16:22MEDIUM (7)Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.NETWORK
CVE-2026-67542026-04-21 13:16:21HIGH (8)Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67532026-04-21 13:16:21HIGH (7)Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67522026-04-21 13:16:21HIGH (7)Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67512026-04-21 13:16:21HIGH (7)Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67502026-04-21 13:16:21HIGH (9)Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67492026-04-21 13:16:21HIGH (8)Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67482026-04-21 13:16:21CRITICAL (10)Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67472026-04-21 13:16:21HIGH (8)Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-67462026-04-21 13:16:21HIGH (8)Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.NETWORK
CVE-2026-57352026-04-07 13:16:48CRITICAL (10)Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.NETWORK
CVE-2026-57342026-04-07 13:16:48CRITICAL (10)Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.NETWORK
CVE-2026-57332026-04-07 13:16:48HIGH (9)Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.NETWORK
CVE-2026-57322026-04-07 13:16:47HIGH (9)Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.NETWORK
CVE-2026-57312026-04-07 13:16:47CRITICAL (10)Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.NETWORK
CVE-2026-47292026-03-24 13:16:09CRITICAL (10)Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149 and Thunderbird 149.NETWORK
CVE-2026-47282026-03-24 13:16:09MEDIUM (7)Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.NETWORK
CVE-2026-47272026-03-24 13:16:09HIGH (8)Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.NETWORK
CVE-2026-47262026-03-24 13:16:08HIGH (8)Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.NETWORK
CVE-2026-47252026-03-24 13:16:08CRITICAL (10)Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.NETWORK
CVE-2026-47242026-03-24 13:16:08CRITICAL (9)Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.NETWORK
CVE-2026-47232026-03-24 13:16:08CRITICAL (10)Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.NETWORK
CVE-2026-47222026-03-24 13:16:08HIGH (9)Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.NETWORK
CVE-2026-47212026-03-24 13:16:08CRITICAL (10)Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47202026-03-24 13:16:08CRITICAL (10)Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47192026-03-24 13:16:08HIGH (8)Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47182026-03-24 13:16:08HIGH (8)Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47172026-03-24 13:16:08CRITICAL (10)Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47162026-03-24 13:16:08CRITICAL (9)Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47152026-03-24 13:16:07CRITICAL (9)Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47142026-03-24 13:16:07HIGH (8)Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47132026-03-24 13:16:07HIGH (8)Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47122026-03-24 13:16:07HIGH (8)Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47112026-03-24 13:16:07CRITICAL (10)Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47102026-03-24 13:16:07CRITICAL (10)Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47092026-03-24 13:16:07HIGH (8)Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47082026-03-24 13:16:07HIGH (8)Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47072026-03-24 13:16:07HIGH (8)Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47062026-03-24 13:16:07HIGH (8)Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47052026-03-24 13:16:06CRITICAL (10)Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47042026-03-24 13:16:06HIGH (8)Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47022026-03-24 13:16:06CRITICAL (10)JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47012026-03-24 13:16:06CRITICAL (10)Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-47002026-03-24 13:16:06CRITICAL (10)Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46992026-03-24 13:16:06HIGH (8)Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46982026-03-24 13:16:06CRITICAL (10)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46972026-03-24 13:16:06HIGH (8)Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46962026-03-24 13:16:06CRITICAL (10)Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46952026-03-24 13:16:05HIGH (8)Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46942026-03-24 13:16:05HIGH (8)Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46932026-03-24 13:16:05HIGH (8)Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46922026-03-24 13:16:05CRITICAL (10)Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46912026-03-24 13:16:05CRITICAL (10)Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46902026-03-24 13:16:05HIGH (9)Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46892026-03-24 13:16:05CRITICAL (10)Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46882026-03-24 13:16:05CRITICAL (10)Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46872026-03-24 13:16:05HIGH (9)Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46862026-03-24 13:16:04HIGH (8)Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46852026-03-24 13:16:04HIGH (8)Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-46842026-03-24 13:16:04HIGH (8)Race condition, use-after-free in the Graphics: WebRender component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.NETWORK
CVE-2026-451732026-06-11 22:16:57HIGH (8)Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21NETWORK
CVE-2026-38472026-03-10 18:19:06HIGH (9)Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148.0.2.NETWORK
CVE-2026-38462026-03-10 18:19:06MEDIUM (7)Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.NETWORK
CVE-2026-38452026-03-10 18:19:06HIGH (9)Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Firefox 148.0.2.NETWORK
CVE-2026-28072026-02-24 14:16:29CRITICAL (10)Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-28062026-02-24 14:16:29CRITICAL (9)Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-28052026-02-24 14:16:29CRITICAL (10)Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-28042026-02-24 14:16:29MEDIUM (5)Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-28032026-02-24 14:16:29HIGH (8)Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-28022026-02-24 14:16:29MEDIUM (4)Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-28012026-02-24 14:16:29HIGH (8)Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-28002026-02-24 14:16:29CRITICAL (10)Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-27992026-02-24 14:16:28CRITICAL (10)Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-27982026-02-24 14:16:28HIGH (9)Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-27972026-02-24 14:16:28CRITICAL (10)Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-27962026-02-24 14:16:28CRITICAL (10)JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-27952026-02-24 14:16:28CRITICAL (10)Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.NETWORK
CVE-2026-27942026-02-24 14:16:28HIGH (8)Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 148.NETWORK
CVE-2026-27932026-02-24 14:16:28CRITICAL (10)Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27922026-02-24 14:16:28CRITICAL (10)Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27912026-02-24 14:16:28CRITICAL (10)Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27902026-02-24 14:16:27CRITICAL (10)Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27892026-02-24 14:16:27CRITICAL (10)Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27882026-02-24 14:16:27CRITICAL (10)Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27872026-02-24 14:16:27CRITICAL (10)Use-after-free in the DOM: Window and Location component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27862026-02-24 14:16:27CRITICAL (10)Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27852026-02-24 14:16:27CRITICAL (10)Invalid pointer in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27842026-02-24 14:16:27CRITICAL (10)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27832026-02-24 14:16:27HIGH (8)Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27822026-02-24 14:16:27CRITICAL (10)Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27812026-02-24 14:16:27CRITICAL (10)Integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, Thunderbird 140.8, and Firefox ESR 115.35.NETWORK
CVE-2026-27802026-02-24 14:16:26CRITICAL (10)Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27792026-02-24 14:16:26CRITICAL (10)Incorrect boundary conditions in the Networking: JAR component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27782026-02-24 14:16:26CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27772026-02-24 14:16:26CRITICAL (10)Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27762026-02-24 14:16:26CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27752026-02-24 14:16:26CRITICAL (10)Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27742026-02-24 14:16:26CRITICAL (10)Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27732026-02-24 14:16:26CRITICAL (10)Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27722026-02-24 14:16:26CRITICAL (10)Use-after-free in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27712026-02-24 14:16:25CRITICAL (10)Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27702026-02-24 14:16:25CRITICAL (10)Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27692026-02-24 14:16:25HIGH (9)Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27682026-02-24 14:16:25CRITICAL (10)Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27672026-02-24 14:16:25CRITICAL (10)Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27662026-02-24 14:16:25CRITICAL (10)Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27652026-02-24 14:16:25CRITICAL (10)Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27642026-02-24 14:16:25CRITICAL (10)JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27632026-02-24 14:16:25CRITICAL (10)Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27622026-02-24 14:16:24CRITICAL (10)Integer overflow in the JavaScript: Standard Library component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27612026-02-24 14:16:24CRITICAL (10)Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27602026-02-24 14:16:24CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27592026-02-24 14:16:24CRITICAL (10)Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27582026-02-24 14:16:24CRITICAL (10)Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-27572026-02-24 14:16:24CRITICAL (10)Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.NETWORK
CVE-2026-26342026-02-24 14:16:24CRITICAL (10)Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability was fixed in Firefox for iOS 147.4.NETWORK
CVE-2026-248692026-01-27 16:16:36HIGH (9)Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.NETWORK
CVE-2026-248682026-01-27 16:16:36MEDIUM (7)Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.NETWORK
CVE-2026-24472026-02-16 15:18:35HIGH (9)Heap buffer overflow in libvpx. This vulnerability was fixed in Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 140.7.2, and Thunderbird 147.0.2.NETWORK
CVE-2026-20322026-02-16 15:18:35MEDIUM (4)Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page content, allowing the attacker to spoof arbitrary HTML under a trusted domain. This vulnerability was fixed in Firefox for iOS 147.2.1.NETWORK
CVE-2026-164122026-07-21 13:17:17CRITICAL (10)Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-164112026-07-21 13:17:17CRITICAL (10)Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164102026-07-21 13:17:16CRITICAL (10)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164092026-07-21 13:17:16HIGH (8)Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164082026-07-21 13:17:16CRITICAL (10)Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164072026-07-21 13:17:16CRITICAL (10)Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164062026-07-21 13:17:16CRITICAL (9)Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164052026-07-21 13:17:16HIGH (8)Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-164032026-07-21 13:17:16MEDIUM (7)Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164022026-07-21 13:17:16CRITICAL (10)Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164012026-07-21 13:17:15HIGH (9)Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-164002026-07-21 13:17:15HIGH (8)Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163992026-07-21 13:17:15HIGH (8)Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163982026-07-21 13:17:15HIGH (8)Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163972026-07-21 13:17:15MEDIUM (7)Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.NETWORK
CVE-2026-163962026-07-21 13:17:15HIGH (9)Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163952026-07-21 13:17:15CRITICAL (10)Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163942026-07-21 13:17:15CRITICAL (9)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163932026-07-21 13:17:15CRITICAL (9)Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163922026-07-21 13:17:14CRITICAL (9)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163912026-07-21 13:17:14HIGH (8)Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163902026-07-21 13:17:14CRITICAL (9)Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163892026-07-21 13:17:14CRITICAL (10)Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163882026-07-21 13:17:14CRITICAL (10)Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163872026-07-21 13:17:14CRITICAL (10)Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163862026-07-21 13:17:14HIGH (8)Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163852026-07-21 13:17:14HIGH (8)Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163842026-07-21 13:17:14HIGH (8)Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163832026-07-21 13:17:13CRITICAL (10)Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163822026-07-21 13:17:13CRITICAL (10)Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163812026-07-21 13:17:13CRITICAL (9)Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163802026-07-21 13:17:13CRITICAL (9)Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163792026-07-21 13:17:13HIGH (9)Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163782026-07-21 13:17:13HIGH (8)Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163772026-07-21 13:17:13CRITICAL (10)Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163762026-07-21 13:17:13HIGH (8)Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163752026-07-21 13:17:13CRITICAL (10)Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163742026-07-21 13:17:13HIGH (8)Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163722026-07-21 13:17:12HIGH (9)Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163712026-07-21 13:17:12HIGH (9)Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163702026-07-21 13:17:07CRITICAL (9)Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163692026-07-21 13:17:07CRITICAL (10)Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163682026-07-21 13:17:05CRITICAL (10)Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163672026-07-21 13:17:05CRITICAL (10)Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163662026-07-21 13:17:05HIGH (9)Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163652026-07-21 13:17:05HIGH (9)Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163642026-07-21 13:17:05CRITICAL (9)Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.NETWORK
CVE-2026-163632026-07-21 13:17:05CRITICAL (10)JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163622026-07-21 13:17:05HIGH (9)Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163612026-07-21 13:17:05CRITICAL (10)Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.NETWORK
CVE-2026-163602026-07-21 13:17:05CRITICAL (10)Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163592026-07-21 13:17:04CRITICAL (9)Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163582026-07-21 13:17:04CRITICAL (10)Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163572026-07-21 13:17:04CRITICAL (10)Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163562026-07-21 13:17:04CRITICAL (10)Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163552026-07-21 13:17:04CRITICAL (10)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163542026-07-21 13:17:04HIGH (8)Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163532026-07-21 13:17:04CRITICAL (10)Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163522026-07-21 13:17:04CRITICAL (10)Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163512026-07-21 13:17:04CRITICAL (10)Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163502026-07-21 13:17:03CRITICAL (10)Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-163492026-07-21 13:17:03CRITICAL (10)Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.NETWORK
CVE-2026-157192026-07-14 13:18:20MEDIUM (5)We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.NETWORK
CVE-2026-157182026-07-14 13:18:20MEDIUM (4)We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13.NETWORK
CVE-2026-142412026-06-30 14:16:26CRITICAL (10)Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.NETWORK
CVE-2026-133562026-07-07 00:16:34MEDIUM (6)A malicious webpage could interrupt a pending navigation by enqueuing a synchronous JavaScript dialog, causing the browser UI to display the destination origin in the address bar while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 152.3.NETWORK
CVE-2026-123302026-06-16 13:16:34MEDIUM (5)Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12.NETWORK
CVE-2026-123292026-06-16 13:16:34MEDIUM (5)Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.NETWORK
CVE-2026-123282026-06-16 13:16:34HIGH (8)Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123272026-06-16 13:16:33HIGH (8)Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123262026-06-16 13:16:33HIGH (8)Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123252026-06-16 13:16:33MEDIUM (7)Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123242026-06-16 13:16:33HIGH (7)Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123232026-06-16 13:16:33MEDIUM (5)Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123222026-06-16 13:16:33MEDIUM (5)Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123212026-06-16 13:16:33MEDIUM (5)JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123202026-06-16 13:16:33MEDIUM (4)Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123192026-06-16 13:16:33MEDIUM (7)Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123182026-06-16 13:16:32HIGH (7)Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123172026-06-16 13:16:32HIGH (8)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123162026-06-16 13:16:32CRITICAL (9)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123152026-06-16 13:16:32CRITICAL (9)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123142026-06-16 13:16:32HIGH (8)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123132026-06-16 13:16:32MEDIUM (5)Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123122026-06-16 13:16:32HIGH (8)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123112026-06-16 13:16:32MEDIUM (5)Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123102026-06-16 13:16:31HIGH (8)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123092026-06-16 13:16:31MEDIUM (7)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123082026-06-16 13:16:31MEDIUM (5)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123072026-06-16 13:16:31MEDIUM (5)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123062026-06-16 13:16:31MEDIUM (5)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123052026-06-16 13:16:31HIGH (8)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123042026-06-16 13:16:31CRITICAL (9)Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123032026-06-16 13:16:31MEDIUM (4)Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123022026-06-16 13:16:30MEDIUM (7)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-123012026-06-16 13:16:30MEDIUM (5)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-123002026-06-16 13:16:30MEDIUM (5)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-122992026-06-16 13:16:30MEDIUM (5)JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122982026-06-16 13:16:30MEDIUM (5)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122972026-06-16 13:16:30CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122962026-06-16 13:16:30CRITICAL (10)Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122952026-06-16 13:16:30CRITICAL (10)Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122942026-06-16 13:16:30CRITICAL (10)Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122932026-06-16 13:16:30CRITICAL (10)Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.NETWORK
CVE-2026-122922026-06-16 13:16:29HIGH (8)Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122912026-06-16 13:16:29HIGH (9)Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122902026-06-16 13:16:29HIGH (8)Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-122892026-06-16 13:16:29HIGH (9)Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.NETWORK
CVE-2026-107022026-06-02 20:16:33MEDIUM (4)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.NETWORK
CVE-2026-107012026-06-02 20:16:33HIGH (8)Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.NETWORK
CVE-2026-08922026-01-13 14:16:40CRITICAL (10)Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147 and Thunderbird 147.NETWORK
CVE-2026-08912026-01-13 14:16:40HIGH (8)Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08902026-01-13 14:16:40MEDIUM (5)Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08892026-01-13 14:16:39HIGH (8)Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.NETWORK
CVE-2026-08882026-01-13 14:16:39MEDIUM (5)Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.NETWORK
CVE-2026-08872026-01-13 14:16:39MEDIUM (4)Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08862026-01-13 14:16:39MEDIUM (5)Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08852026-01-13 14:16:39MEDIUM (7)Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08842026-01-13 14:16:39CRITICAL (10)Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08832026-01-13 14:16:39MEDIUM (5)Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08822026-01-13 14:16:39HIGH (9)Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08812026-01-13 14:16:39CRITICAL (10)Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.NETWORK
CVE-2026-08802026-01-13 14:16:39HIGH (9)Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08792026-01-13 14:16:38CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08782026-01-13 14:16:38HIGH (8)Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2026-08772026-01-13 14:16:38HIGH (8)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.NETWORK
CVE-2025-91872025-08-19 21:15:31CRITICAL (10)Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142 and Thunderbird < 142.NETWORK
CVE-2025-91862025-08-19 21:15:31MEDIUM (7)Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142.NETWORK
CVE-2025-91852025-08-19 21:15:31HIGH (8)Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.NETWORK
CVE-2025-91842025-08-19 21:15:31HIGH (8)Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2.NETWORK
CVE-2025-91832025-08-19 21:15:31MEDIUM (7)Spoofing issue in the Address Bar component. This vulnerability affects Firefox < 142 and Firefox ESR < 140.2.NETWORK
CVE-2025-91822025-08-19 21:15:31HIGH (8)Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2.NETWORK
CVE-2025-91812025-08-19 21:15:31MEDIUM (7)Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.NETWORK
CVE-2025-91802025-08-19 21:15:30HIGH (8)Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.NETWORK
CVE-2025-91792025-08-19 21:15:30CRITICAL (10)An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.NETWORK
CVE-2025-83642025-08-19 21:15:30MEDIUM (4)A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141.NETWORK
CVE-2025-80442025-07-22 21:15:51CRITICAL (10)Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141 and Thunderbird < 141.NETWORK
CVE-2025-80432025-07-22 21:15:51CRITICAL (10)Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability affects Firefox < 141 and Thunderbird < 141.NETWORK
CVE-2025-80422025-08-19 21:15:29CRITICAL (10)Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.NETWORK
CVE-2025-80412025-08-19 21:15:29MEDIUM (5)In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141.NETWORK
CVE-2025-80402025-07-22 21:15:51HIGH (9)Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.NETWORK
CVE-2025-80392025-07-22 21:15:51HIGH (8)In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.NETWORK
CVE-2025-80382025-07-22 21:15:51CRITICAL (10)Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.NETWORK
CVE-2025-80372025-07-22 21:15:51CRITICAL (9)Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.NETWORK
CVE-2025-80362025-07-22 21:15:51HIGH (8)Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.NETWORK
CVE-2025-80352025-07-22 21:15:51HIGH (9)Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-80342025-07-22 21:15:51HIGH (9)Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-80332025-07-22 21:15:50MEDIUM (7)The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-80322025-07-22 21:15:50HIGH (8)XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-80312025-07-22 21:15:50CRITICAL (10)The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-80302025-07-22 21:15:50HIGH (8)Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-80292025-07-22 21:15:50HIGH (8)Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-80282025-07-22 21:15:50CRITICAL (10)On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-80272025-07-22 21:15:50MEDIUM (7)On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.NETWORK
CVE-2025-64362025-06-24 13:15:25HIGH (8)Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 140 and Thunderbird < 140.NETWORK
CVE-2025-64352025-06-24 13:15:25HIGH (8)If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability affects Firefox < 140 and Thunderbird < 140.NETWORK
CVE-2025-64342025-06-24 13:15:24MEDIUM (4)The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140.NETWORK
CVE-2025-64332025-06-24 13:15:24CRITICAL (10)If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140 and Thunderbird < 140.NETWORK
CVE-2025-64322025-06-24 13:15:24HIGH (9)When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox < 140 and Thunderbird < 140.NETWORK
CVE-2025-64312025-06-24 13:15:24MEDIUM (7)When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have bypassed this prompt, potentially exposing the user to security vulnerabilities or privacy leaks in external applications. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.NETWORK
CVE-2025-64302025-06-24 13:15:24MEDIUM (6)When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `&lt;embed&gt;` or `&lt;object&gt;` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.NETWORK
CVE-2025-64292025-06-24 13:15:24MEDIUM (7)Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.NETWORK
CVE-2025-64282025-06-24 13:15:24MEDIUM (4)When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140.NETWORK
CVE-2025-64272025-06-24 13:15:24CRITICAL (9)An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.NETWORK
CVE-2025-64262025-06-24 13:15:24HIGH (9)The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.NETWORK
CVE-2025-64252025-06-24 13:15:23MEDIUM (4)An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.NETWORK
CVE-2025-64242025-06-24 13:15:23CRITICAL (10)A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.NETWORK
CVE-2025-550312025-08-19 21:15:28CRITICAL (10)Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the target account. This vulnerability affects Firefox for iOS < 142 and Focus for iOS < 142.NETWORK
CVE-2025-550302025-08-19 21:15:28MEDIUM (6)Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, potentially allowing for XSS attacks This vulnerability affects Firefox for iOS < 142.NETWORK
CVE-2025-550292025-08-19 21:15:28HIGH (8)Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks This vulnerability affects Firefox for iOS < 142.NETWORK
CVE-2025-550282025-08-19 21:15:28MEDIUM (7)Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks This vulnerability affects Firefox for iOS < 142.NETWORK
CVE-2025-541452025-08-19 21:15:28CRITICAL (9)The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme This vulnerability affects Firefox for iOS < 141.NETWORK
CVE-2025-541442025-08-19 21:15:28MEDIUM (5)The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a user was tricked into clicking a link This vulnerability affects Firefox for iOS < 141.NETWORK
CVE-2025-541432025-08-19 21:15:28CRITICAL (10)Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141.NETWORK
CVE-2025-52722025-05-27 13:15:23HIGH (7)Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139 and Thunderbird < 139.NETWORK
CVE-2025-52712025-05-27 13:15:23MEDIUM (7)Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability affects Firefox < 139 and Thunderbird < 139.NETWORK
CVE-2025-52702025-05-27 13:15:23HIGH (8)In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139 and Thunderbird < 139.NETWORK
CVE-2025-52692025-05-27 13:15:23MEDIUM (8)Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.11 and Thunderbird < 128.11.NETWORK
CVE-2025-52682025-05-27 13:15:23MEDIUM (8)Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.NETWORK
CVE-2025-52672025-05-27 13:15:23MEDIUM (5)A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.NETWORK
CVE-2025-52662025-05-27 13:15:22MEDIUM (7)Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.NETWORK
CVE-2025-52652025-05-27 13:15:22MEDIUM (5)Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.LOCAL
CVE-2025-52642025-05-27 13:15:22MEDIUM (5)Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.LOCAL
CVE-2025-52632025-05-27 13:15:22MEDIUM (4)Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.NETWORK
CVE-2025-50202025-05-21 18:15:54MEDIUM (4)Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client This vulnerability affects Firefox for iOS < 139.NETWORK
CVE-2025-497102025-06-11 12:15:27CRITICAL (10)An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4.NETWORK
CVE-2025-497092025-06-11 12:15:27CRITICAL (10)Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4.NETWORK
CVE-2025-49192025-05-17 22:15:20HIGH (9)An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.NETWORK
CVE-2025-49182025-05-17 22:15:20CRITICAL (10)An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.NETWORK
CVE-2025-40932025-04-29 14:15:36HIGH (8)Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 128.10 and Thunderbird < 128.10.NETWORK
CVE-2025-40922025-04-29 14:15:36MEDIUM (7)Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138 and Thunderbird < 138.NETWORK
CVE-2025-40912025-04-29 14:15:36HIGH (8)Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.NETWORK
CVE-2025-40902025-04-29 14:15:36MEDIUM (5)A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability affects Firefox < 138 and Thunderbird < 138.NETWORK
CVE-2025-40892025-04-29 14:15:36MEDIUM (5)Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 138 and Thunderbird < 138.LOCAL
CVE-2025-40882025-04-29 14:15:35MEDIUM (7)A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invoked the Storage Access API. This enabled potential Cross-Site Request Forgery attacks across origins. This vulnerability affects Firefox < 138 and Thunderbird < 138.NETWORK
CVE-2025-40872025-04-29 14:15:35MEDIUM (5)A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10.NETWORK
CVE-2025-40862025-04-29 14:15:35MEDIUM (7)A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138 and Thunderbird < 138.NETWORK
CVE-2025-40852025-04-29 14:15:35HIGH (7)An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. This vulnerability affects Firefox < 138 and Thunderbird < 138.NETWORK
CVE-2025-40842025-04-29 14:15:35MEDIUM (6)Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox ESR < 128.10, Firefox ESR < 115.23, and Thunderbird < 128.10.NETWORK
CVE-2025-40832025-04-29 14:15:35CRITICAL (9)A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.NETWORK
CVE-2025-40822025-04-29 14:15:35MEDIUM (6)Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.NETWORK
CVE-2025-36082025-04-15 13:15:56MEDIUM (7)A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability affects Firefox < 137.0.2.NETWORK
CVE-2025-30352025-04-01 13:15:42MEDIUM (5)By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability affects Firefox < 137.NETWORK
CVE-2025-30342025-04-01 13:15:42HIGH (8)Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137 and Thunderbird < 137.NETWORK
CVE-2025-30332025-04-01 13:15:42HIGH (8)After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 137 and Thunderbird < 137.LOCAL
CVE-2025-30322025-04-01 13:15:42HIGH (7)Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability affects Firefox < 137 and Thunderbird < 137.NETWORK
CVE-2025-30312025-04-01 13:15:41MEDIUM (7)An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability affects Firefox < 137 and Thunderbird < 137.NETWORK
CVE-2025-30302025-04-01 13:15:41HIGH (8)Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.NETWORK
CVE-2025-30292025-04-01 13:15:41HIGH (7)A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.NETWORK
CVE-2025-30282025-04-01 13:15:41MEDIUM (7)JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.NETWORK
CVE-2025-28572025-03-27 14:15:56CRITICAL (10)Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 136.0.4, Firefox ESR < 128.8.1, and Firefox ESR < 115.21.1.NETWORK
CVE-2025-28172025-04-29 14:15:32HIGH (9)Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege escalation. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.NETWORK
CVE-2025-274262025-03-04 14:15:40MEDIUM (5)Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL This vulnerability affects Firefox for iOS < 136.NETWORK
CVE-2025-274252025-03-04 14:15:39MEDIUM (4)Scanning certain QR codes that included text with a website URL could allow the URL to be opened without presenting the user with a confirmation alert first This vulnerability affects Firefox for iOS < 136.NETWORK
CVE-2025-274242025-03-04 14:15:39MEDIUM (4)Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.NETWORK
CVE-2025-231092025-01-11 04:15:06MEDIUM (7)Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address This vulnerability affects Firefox for iOS < 134.NETWORK
CVE-2025-231082025-01-11 04:15:06MEDIUM (4)Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.NETWORK
CVE-2025-19432025-03-04 14:15:39HIGH (8)Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Thunderbird < 136.NETWORK
CVE-2025-19422025-03-04 14:15:39CRITICAL (10)When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.NETWORK
CVE-2025-19412025-03-04 14:15:39CRITICAL (9)Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.NETWORK
CVE-2025-19402025-03-04 14:15:39HIGH (7)A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 136.NETWORK
CVE-2025-19392025-03-04 14:15:39LOW (4)Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.LOCAL
CVE-2025-19382025-03-04 14:15:39MEDIUM (7)Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-19372025-03-04 14:15:39HIGH (8)Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-19362025-03-04 14:15:39HIGH (7)jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-19352025-03-04 14:15:38MEDIUM (4)A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-19342025-03-04 14:15:38MEDIUM (7)It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-19332025-03-04 14:15:38HIGH (8)On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-19322025-03-04 14:15:38HIGH (8)An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-19312025-03-04 14:15:38HIGH (8)It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-19302025-03-04 14:15:38HIGH (9)On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.NETWORK
CVE-2025-148612025-12-18 15:15:53HIGH (9)Memory safety bugs present in Firefox 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146.0.1.NETWORK
CVE-2025-148602025-12-18 15:15:53CRITICAL (10)Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.NETWORK
CVE-2025-147442025-12-18 15:15:53MEDIUM (7)Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability was fixed in Firefox for iOS 144.0.NETWORK
CVE-2025-143332025-12-09 16:17:41HIGH (8)Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143322025-12-09 16:17:41HIGH (7)Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146 and Thunderbird 146.NETWORK
CVE-2025-143312025-12-09 16:17:41MEDIUM (7)Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143302025-12-09 16:17:41CRITICAL (10)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143292025-12-09 16:17:41HIGH (9)Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143282025-12-09 16:17:40HIGH (9)Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143272025-12-09 16:17:40HIGH (8)Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.NETWORK
CVE-2025-143262025-12-09 16:17:40CRITICAL (10)Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.NETWORK
CVE-2025-143252025-12-09 16:17:40HIGH (7)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143242025-12-09 16:17:40CRITICAL (10)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143232025-12-09 16:17:40HIGH (9)Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143222025-12-09 16:17:40HIGH (8)Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-143212025-12-09 16:17:39CRITICAL (10)Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.NETWORK
CVE-2025-14142025-02-18 14:15:29MEDIUM (7)Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135.0.1.NETWORK
CVE-2025-130272025-11-11 16:15:40HIGH (8)Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 145 and Thunderbird 145.NETWORK
CVE-2025-130262025-11-11 16:15:40CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.NETWORK
CVE-2025-130252025-11-11 16:15:40HIGH (8)Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.NETWORK
CVE-2025-130242025-11-11 16:15:40CRITICAL (10)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.NETWORK
CVE-2025-130232025-11-11 16:15:39CRITICAL (10)Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.NETWORK
CVE-2025-130222025-11-11 16:15:39CRITICAL (10)Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.NETWORK
CVE-2025-130212025-11-11 16:15:39CRITICAL (10)Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.NETWORK
CVE-2025-130202025-11-11 16:15:39HIGH (9)Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.NETWORK
CVE-2025-130192025-11-11 16:15:39HIGH (8)Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.NETWORK
CVE-2025-130182025-11-11 16:15:39HIGH (8)Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.NETWORK
CVE-2025-130172025-11-11 16:15:39HIGH (8)Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.NETWORK
CVE-2025-130162025-11-11 16:15:39HIGH (8)Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.NETWORK
CVE-2025-130152025-11-11 16:15:39LOW (3)Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30.NETWORK
CVE-2025-130142025-11-11 16:15:38HIGH (9)Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.NETWORK
CVE-2025-130132025-11-11 16:15:38MEDIUM (6)Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.NETWORK
CVE-2025-130122025-11-11 16:15:38HIGH (8)Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Thunderbird 140.5.NETWORK
CVE-2025-123802025-10-28 14:15:58CRITICAL (10)Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-related IPC calls. This may have been usable to escape the child process sandbox. This vulnerability was fixed in Firefox 144.0.2.NETWORK
CVE-2025-117212025-10-14 13:15:39CRITICAL (10)Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144 and Thunderbird 144.NETWORK
CVE-2025-117202025-10-14 13:15:38HIGH (8)The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability was fixed in Firefox 144.NETWORK
CVE-2025-117192025-10-14 13:15:38CRITICAL (10)Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.NETWORK
CVE-2025-117182025-10-14 13:15:38MEDIUM (7)When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event. This vulnerability was fixed in Firefox 144.NETWORK
CVE-2025-117172025-10-14 13:15:38CRITICAL (9)When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one being used. Prior to Firefox 144 the password edit screen was visible. This vulnerability was fixed in Firefox 144.NETWORK
CVE-2025-117162025-10-14 13:15:38MEDIUM (7)Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144.NETWORK
CVE-2025-117152025-10-14 13:15:38HIGH (9)Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.NETWORK
CVE-2025-117142025-10-14 13:15:38HIGH (9)Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.NETWORK
CVE-2025-117132025-10-14 13:15:38HIGH (8)Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.NETWORK
CVE-2025-117122025-10-14 13:15:37MEDIUM (6)A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.NETWORK
CVE-2025-117112025-10-14 13:15:37MEDIUM (7)There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.NETWORK
CVE-2025-117102025-10-14 13:15:37CRITICAL (10)A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.NETWORK
CVE-2025-117092025-10-14 13:15:37CRITICAL (10)A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.NETWORK
CVE-2025-117082025-10-14 13:15:37CRITICAL (10)Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.NETWORK
CVE-2025-111532025-09-30 13:15:49HIGH (8)JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 143.0.3.NETWORK
CVE-2025-111522025-09-30 13:15:49HIGH (9)Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143.0.3.NETWORK
CVE-2025-108592025-09-30 13:15:49MEDIUM (4)Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Incognito mode even after the user closed all tabs This vulnerability affects Firefox for iOS < 143.1.LOCAL
CVE-2025-105372025-09-16 13:15:49HIGH (9)Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.NETWORK
CVE-2025-105362025-09-16 13:15:49MEDIUM (6)Information disclosure in the Networking: Cache component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.LOCAL
CVE-2025-105352025-09-16 13:15:49HIGH (8)Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability affects Firefox < 143.NETWORK
CVE-2025-105342025-09-16 13:15:48HIGH (8)Spoofing issue in the Site Permissions component. This vulnerability affects Firefox < 143 and Thunderbird < 143.NETWORK
CVE-2025-105332025-09-16 13:15:48HIGH (9)Integer overflow in the SVG component. This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.NETWORK
CVE-2025-105322025-09-16 13:15:47MEDIUM (7)Incorrect boundary conditions in the JavaScript: GC component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.NETWORK
CVE-2025-105312025-09-16 13:15:47MEDIUM (5)Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability affects Firefox < 143 and Thunderbird < 143.NETWORK
CVE-2025-105302025-09-16 13:15:46MEDIUM (7)Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability affects Firefox < 143 and Thunderbird < 143.NETWORK
CVE-2025-105292025-09-16 13:15:46MEDIUM (7)Same-origin policy bypass in the Layout component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.NETWORK
CVE-2025-105282025-09-16 13:15:45HIGH (7)Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.NETWORK
CVE-2025-105272025-09-16 13:15:44HIGH (7)Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.NETWORK
CVE-2025-10202025-02-04 14:15:33CRITICAL (10)Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135 and Thunderbird < 135.NETWORK
CVE-2025-10192025-02-04 14:15:33MEDIUM (4)The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.NETWORK
CVE-2025-10182025-02-04 14:15:33MEDIUM (5)The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135.NETWORK
CVE-2025-10172025-02-04 14:15:33CRITICAL (10)Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.NETWORK
CVE-2025-10162025-02-04 14:15:32CRITICAL (10)Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.NETWORK
CVE-2025-10142025-02-04 14:15:32HIGH (9)Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.NETWORK

Showing the 500 most recent of 2772 tracked CVEs.

Why keeping Firefox patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Firefox release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches Firefox

Lavawall® watches Firefox releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Firefox, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of Firefox?
Lavawall tracks Firefox at version 153.0.3 (last checked 2026-08-10). New releases are monitored continuously and can be deployed automatically across your fleet.
Does Firefox have known security vulnerabilities (CVEs)?
Lavawall continuously monitors Firefox for newly disclosed CVEs and remediates them automatically as they appear.
How do I patch Firefox automatically?
Deploy the Lavawall® agent and Firefox updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for Firefox through public information and proprietary statistical analysis, and can patch it automatically across your fleet.