Mozilla Foundation Security Advisory 2026-85
Security Vulnerabilities fixed in Firefox ESR 153.2
- Announced
- September 1, 2026
- Impact
- high
- Products
- Firefox ESR
- Fixed in
-
- Firefox ESR 153.2
#CVE-2026-75874: Sandbox escape in the Remote Settings Client component
- Reporter
- crixer
- Impact
- high
References
#CVE-2026-84118: Use-after-free in the JavaScript: GC component
- Reporter
- x0e
- Impact
- high
References
#CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84120: Use-after-free in the Audio/Video component
- Reporter
- Ukyo Akai
- Impact
- high
References
#CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84122: Use-after-free in the Audio/Video component
- Reporter
- Hyeonjun Ahn
- Impact
- high
References
#CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
- Reporter
- Hyeonjun Ahn
- Impact
- high
References
#CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-74952: Privilege escalation in the Application Update component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-84129: Site isolation issue in the DOM: Navigation component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component
- Reporter
- navapon
- Impact
- moderate
References
#CVE-2026-84132: Information disclosure in the Networking: HTTP component
- Reporter
- Shu Takahashi
- Impact
- moderate
References
#CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component
- Reporter
- pakhunov.anton.n
- Impact
- low
References
#CVE-2026-84134: Other issue in the Profile Backup component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-84136: Other issue in the DOM: Navigation component
- Reporter
- Apentota
- Impact
- low
References
#CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
- Reporter
- Riski Muhammad Ivan
- Impact
- low
References
#CVE-2026-84139: Clickjacking issue in the DOM: Events component
- Reporter
- Long Nguyen
- Impact
- low
References
#CVE-2026-84140: Site isolation issue in the DOM: Navigation component
- Reporter
- Mohamed Mbarek
- Impact
- low
References
#CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
- Reporter
- nguyentuanhung1149
- Impact
- low
References
#CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15
- Reporter
- Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox 154, Firefox ESR 153.1 and Firefox ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
- Reporter
- Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
- Reporter
- Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
- High Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
- Moderate Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40
- Low Severity internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40