Mozilla Foundation Security Advisory 2026-82
Security Vulnerabilities fixed in Firefox 155
- Announced
- September 1, 2026
- Impact
- high
- Products
- Firefox
- Fixed in
-
- Firefox 155
#CVE-2026-84117: Privilege escalation in Firefox for Android
- Reporter
- HiWorld
- Impact
- high
References
#CVE-2026-84118: Use-after-free in the JavaScript: GC component
- Reporter
- x0e
- Impact
- high
References
#CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84120: Use-after-free in the Audio/Video component
- Reporter
- Ukyo Akai
- Impact
- high
References
#CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84122: Use-after-free in the Audio/Video component
- Reporter
- Hyeonjun Ahn
- Impact
- high
References
#CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
- Reporter
- Hyeonjun Ahn
- Impact
- high
References
#CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84126: Incorrect boundary conditions in the Layout: Grid component
- Reporter
- Irvan Kurniawan
- Impact
- high
References
#CVE-2026-84127: Information disclosure in the WebExtensions component in Firefox for Android
- Reporter
- Wladimir Palant
- Impact
- moderate
References
#CVE-2026-84128: Privilege escalation in the WebDriver BiDi component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-84129: Site isolation issue in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component
- Reporter
- navapon
- Impact
- moderate
References
#CVE-2026-84132: Information disclosure in the Networking: HTTP component
- Reporter
- Shu Takahashi
- Impact
- moderate
References
#CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component
- Reporter
- pakhunov.anton.n
- Impact
- low
References
#CVE-2026-84134: Other issue in the Profile Backup component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-84135: Other issue in Firefox Focus for Android
- Reporter
- Atsushi Sada
- Impact
- low
References
#CVE-2026-84136: Other issue in the DOM: Navigation component
- Reporter
- Apentota
- Impact
- low
References
#CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
- Reporter
- Riski Muhammad Ivan
- Impact
- low
References
#CVE-2026-84138: Denial-of-service in the PDF Viewer component
- Reporter
- Uwez Khan
- Impact
- low
References
#CVE-2026-84139: Clickjacking issue in the DOM: Events component
- Reporter
- Long Nguyen
- Impact
- low
References
#CVE-2026-84140: Site isolation issue in the DOM: Navigation component
- Reporter
- Mohamed Mbarek
- Impact
- low
References
#CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
- Reporter
- nguyentuanhung1149
- Impact
- low
References
#CVE-2026-84142: Internally found bugs fixed in Firefox 155
- Reporter
- Alexandre Poirot, Christian Holler, Sebastian Hengst and the Mozilla Fuzzing Team
- Impact
- moderate
Description
Internally found bugs present in Firefox 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
- Reporter
- Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Firefox ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
- Reporter
- Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
- Reporter
- Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
- High Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
- Moderate Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
- Low Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40