Opened 3 weeks ago
Closed 3 weeks ago
#23937 closed enhancement (fixed)
firefox-153.3.0esr
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | high | Keywords: | |
| Cc: |
Description
Release notes not available yet.
Change History (4)
comment:1 by , 3 weeks ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 3 weeks ago
comment:3 by , 3 weeks ago
| Milestone: | 13.2 → 98-Security |
|---|---|
| Owner: | changed from to |
| Priority: | normal → high |
| Severity: | normal → high |
| Status: | assigned → new |
Security fixes:
- CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2026-92015: Privilege escalation in the WebExtensions component (high)
- CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component (high)
- CVE-2026-92016: Use-after-free in the Disability Access APIs component (high)
- CVE-2026-92017: Privilege escalation in the DOM: Service Workers component (high)
- CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component (high)
- CVE-2026-92019: Mitigation bypass in the Remote Settings Client component (high)
- CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component (high)
- CVE-2026-92022: Use-after-free in the DOM: HTML Parser component (high)
- CVE-2026-92023: Use-after-free in the XML component (high)
- CVE-2026-92024: Use-after-free in the SVG component (high)
- CVE-2026-92025: Use-after-free in the DOM: Navigation component (high)
- CVE-2026-92026: Use-after-free in the Networking component (high)
- CVE-2026-92027: Use-after-free in the DOM: Streams component (high)
- CVE-2026-92028: Use-after-free in the DOM: Core & HTML component (high)
- CVE-2026-92029: Use-after-free in the SVG component (high)
- CVE-2026-92038: Mitigation bypass in the Remote Settings Client component (high)
- CVE-2026-92039: Mitigation bypass in the DOM: Notifications component (moderate)
- CVE-2026-92041: Mitigation bypass in the DOM: Networking component (moderate)
- CVE-2026-92042: Race condition in the DOM: Content Processes component (moderate)
- CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component (moderate)
- CVE-2026-92044: Information disclosure in the Networking: HTTP component (moderate)
- - CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component (moderate)
- CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component (moderate)
- CVE-2026-92046: Use-after-free in the Graphics component (moderate)
- CVE-2026-92047: Privilege escalation in the Crash Reporting component (moderate)
- CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component (moderate)
- CVE-2026-92049: Use-after-free in the Widget: Win32 component (moderate)
- CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component (moderate)
- CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component (moderate)
- CVE-2026-92054: Privilege escalation in the Memory component (moderate)
- CVE-2026-92055: Privilege escalation in the DevTools component (moderate)
- CVE-2026-92056: Use-after-free in the Graphics: Text component (moderate)
- CVE-2026-92057: Mitigation bypass in the Enterprise Policies component (moderate)
- CVE-2026-92031: Information disclosure in the Graphics: ImageLib component (moderate)
- CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component (moderate)
- CVE-2026-92058: Use-after-free in the Graphics component (moderate)
- CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component (moderate)
- CVE-2026-92060: Use-after-free in the Internationalization component (low)
- CVE-2026-92062: Privilege escalation in the Session Restore component (low)
- CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component (low)
- CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component (low)
- CVE-2026-92067: Use-after-free in the Widget: Gtk component (low)
- CVE-2026-92068: Site isolation issue in the Reader Mode component (low)
- CVE-2026-92069: Spoofing issue in the DOM: Navigation component (low)
- CVE-2026-92070: Information disclosure in the Networking component (low)
- CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component (low)
- CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component (low)
- CVE-2026-92073: Privilege escalation in the Enterprise Policies component (low)
- CVE-2026-92074: Mitigation bypass in the Popup Blocker component (low)
- CVE-2026-92075: Mitigation bypass in the Networking component (low)
- CVE-2026-92076: Incorrect boundary conditions in the Networking component (low)
- CVE-2026-92077: Denial-of-service in the SVG component (low)
- CVE-2026-92078: Denial-of-service in the Security component (low)
- CVE-2026-92079: Mitigation bypass in the Widget: Win32 component (low)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/
comment:4 by , 3 weeks ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.1-026 has been issued.
Note:
See TracTickets
for help on using tickets.

Fixed at 7f9f7fadbf. Leaving open until release notes are available.