Mozilla Foundation Security Advisory 2026-69

Security Vulnerabilities fixed in Firefox ESR 115.38

Announced
July 21, 2026
Impact
critical
Products
Firefox ESR
Fixed in
  • Firefox ESR 115.38

#CVE-2026-15719: Site isolation issue in the DOM: Navigation component

Reporter
Atsushi Sada
Impact
critical
Description

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.

References

#CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component

Reporter
Tran Quac
Impact
high
References

#CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component

Reporter
Tomoya Nakanishi
Impact
high
References

#CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component

Reporter
Yaqoub Aldurayhim
Impact
high
References

#CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component

Reporter
Oskar L
Impact
high
References

#CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component

Reporter
fedek
Impact
high
References

#CVE-2026-16354: Information disclosure in the Graphics: ImageLib component

Reporter
satyamasd
Impact
high
References

#CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component

Reporter
Amy Burnett of OpenAI
Impact
high
References

#CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component

Reporter
Oskar L
Impact
high
References

#CVE-2026-16357: Incorrect boundary conditions in the Graphics component

Reporter
5up3rh3i
Impact
high
References

#CVE-2026-16358: Site isolation issue in the Graphics: WebRender component

Reporter
Hcamael
Impact
moderate
References

#CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component

Reporter
Jacolon Walker
Impact
moderate
References

#CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153

Reporter
Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla and the Mozilla Fuzzing Team
Impact
high
Description

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

References

#CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13

Reporter
The Mozilla Fuzzing Team
Impact
high
Description

Memory safety bugs present in Firefox ESR 115.37 and Firefox ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

References