Opened 6 weeks ago
Closed 6 weeks ago
#23763 closed enhancement (fixed)
firefox-153.1.0esr
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | high | Keywords: | |
| Cc: |
Description
New minor release. Release notes not available yet but most likely a security update.
Change History (3)
comment:1 by , 6 weeks ago
comment:2 by , 6 weeks ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Priority: | normal → elevated |
| Severity: | normal → high |
| Status: | assigned → new |
Security fixes:
- CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component (high)
- CVE-2026-74935: Privilege escalation in the DOM: Networking component (high)
- CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component (high)
- CVE-2026-74937: Use-after-free in the JavaScript: GC component (high)
- CVE-2026-74938: Mitigation bypass in the JavaScript: GC component (high)
- CVE-2026-74939: Privilege escalation in the DOM: Navigation component (high)
- CVE-2026-74940: Use-after-free in the Graphics: Text component (high)
- CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component (high)
- CVE-2026-74942: Privilege escalation in the Remote Settings Client component (high)
- CVE-2026-74943: Use-after-free in the Graphics: ImageLib component (high)
- CVE-2026-74944: Use-after-free in the DOM: Core & HTML component (high)
- CVE-2026-74945: Information disclosure in the Graphics: Text component (high)
- CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component (high)
- CVE-2026-74948: Information disclosure in the Graphics component (high)
- CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component (high)
- CVE-2026-74950: Privilege escalation in the Downloads API component (moderate)
- CVE-2026-74953: Privilege escalation in the Networking: Cookies component (moderate)
- CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component (moderate)
- CVE-2026-74955: Privilege escalation in the Request Handling component (moderate)
- CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component (moderate)
- CVE-2026-74957: Mitigation bypass in the Safe Browsing component (moderate)
- CVE-2026-74958: Information disclosure in the WebRTC component (moderate)
- CVE-2026-74959: Mitigation bypass in the Storage: Cache API component (moderate)
- CVE-2026-74960: Site isolation issue in the WebExtensions component (moderate)
- CVE-2026-74961: Side-channel in the Web Audio component (moderate)
- CVE-2026-74962: Site isolation issue in the Networking: Cookies component (moderate)
- CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component (moderate)
- CVE-2026-74964: Integer overflow in the Graphics component (moderate)
- CVE-2026-74965: Privilege escalation in the Shell Integration component (moderate)
- CVE-2026-74966: Information disclosure in the Form Autofill component (moderate)
- CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component (moderate)
- CVE-2026-74968: Site isolation issue in the Graphics: WebRender component (moderate)
- CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component (moderate)
- CVE-2026-74970: Site isolation issue in the Graphics component (moderate)
- CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component (moderate)
- CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component (moderate)
- CVE-2026-74973: Race condition, use-after-free in the Graphics component (moderate)
- CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component (moderate)
- CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component (low)
- CVE-2026-74977: Integer overflow in the Graphics component (low)
- CVE-2026-74978: Clickjacking issue in the Widget component (low)
- CVE-2026-74979: Mitigation bypass in the Add-ons Manager component (low)
- CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component (low)
- CVE-2026-74982: Denial-of-service in the Widget component (low)
- CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component (low)
- CVE-2026-74984: Race condition in the JavaScript Engine component (low)
- CVE-2026-74985: Privilege escalation in the Enterprise Policies component (low)
- CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component (low)
- CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 (high)
- CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 (high)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/
comment:3 by , 6 weeks ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-203 has been issued.
Note:
See TracTickets
for help on using tickets.

Fixed at a538077057. Leaving open until release notes are published.