Firefox Mozilla Firefox Open source web browser

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Mozilla Firefox.

Recent Mozilla Firefox Security Advisories

Advisory Title Published
mfsa2026-82 Security Vulnerabilities fixed in Firefox 155 mfsa2026-82 September 1, 2026
mfsa2026-83 Security Vulnerabilities fixed in Firefox ESR 115.40 mfsa2026-83 September 1, 2026
mfsa2026-84 Security Vulnerabilities fixed in Firefox ESR 140.15 mfsa2026-84 September 1, 2026
mfsa2026-85 Security Vulnerabilities fixed in Firefox ESR 153.2 mfsa2026-85 September 1, 2026
mfsa2026-81 Security Vulnerabilities fixed in Firefox for iOS 155.0 mfsa2026-81 August 31, 2026
mfsa2026-74 Security Vulnerabilities fixed in Firefox 154 mfsa2026-74 August 18, 2026
mfsa2026-75 Security Vulnerabilities fixed in Firefox ESR 115.39 mfsa2026-75 August 18, 2026
mfsa2026-77 Security Vulnerabilities fixed in Firefox ESR 153.1 mfsa2026-77 August 18, 2026
mfsa2026-76 Security Vulnerabilities fixed in Firefox ESR 140.14 mfsa2026-76 August 18, 2026
mfsa2026-73 Security Vulnerabilities fixed in Firefox for Android 153.0.3 mfsa2026-73 August 4, 2026

Known Exploited Mozilla Firefox Vulnerabilities

The following Mozilla Firefox vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
CVE-2024-9680 Exploit Probability: 23.2%
October 15, 2024
Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-4495 Exploit Probability: 71.4%
May 25, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
CVE-2022-26486 Exploit Probability: 2.3%
March 7, 2022
Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
CVE-2022-26485 Exploit Probability: 13.8%
March 7, 2022
Mozilla Firefox Information Disclosure Vulnerability Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
CVE-2013-1675 Exploit Probability: 6.7%
March 3, 2022

The vulnerability CVE-2015-4495: Mozilla Firefox Security Feature Bypass Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited Mozilla Firefox vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

EOL Dates

Ensure that you are using a supported version of Mozilla Firefox. Here are some end of life, and end of support dates for Mozilla Firefox.

Release EOL Date Status
155 -
Active

154 September 1, 2026
EOL

Mozilla Firefox 154 became EOL in 2026.

153 -
Active

152 July 21, 2026
EOL

Mozilla Firefox 152 became EOL in 2026.

151 June 16, 2026
EOL

Mozilla Firefox 151 became EOL in 2026.

150 May 18, 2026
EOL

Mozilla Firefox 150 became EOL in 2026.

149 April 21, 2026
EOL

Mozilla Firefox 149 became EOL in 2026.

148 March 24, 2026
EOL

Mozilla Firefox 148 became EOL in 2026.

147 February 24, 2026
EOL

Mozilla Firefox 147 became EOL in 2026.

146 January 13, 2026
EOL

Mozilla Firefox 146 became EOL in 2026.

145 December 9, 2025
EOL

Mozilla Firefox 145 became EOL in 2025.

144 November 11, 2025
EOL

Mozilla Firefox 144 became EOL in 2025.

143 October 14, 2025
EOL

Mozilla Firefox 143 became EOL in 2025.

142 September 16, 2025
EOL

Mozilla Firefox 142 became EOL in 2025.

141 August 19, 2025
EOL

Mozilla Firefox 141 became EOL in 2025.

140 September 29, 2026
EOL This Year

Mozilla Firefox 140 will become EOL this year, in September 2026.

139 June 24, 2025
EOL

Mozilla Firefox 139 became EOL in 2025.

138 May 27, 2025
EOL

Mozilla Firefox 138 became EOL in 2025.

137 April 29, 2025
EOL

Mozilla Firefox 137 became EOL in 2025.

136 April 1, 2025
EOL

Mozilla Firefox 136 became EOL in 2025.

By the Year

In 2026 there have been 420 vulnerabilities in Mozilla Firefox with an average score of 7.8 out of ten. Last year, in 2025 Firefox had 189 security vulnerabilities published. That is, 231 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.26.




Year Vulnerabilities Average Score
2026 420 7.81
2025 189 7.54
2024 190 7.15
2023 180 7.38
2022 159 7.44
2021 123 7.13
2020 148 7.27
2019 121 7.44
2018 312 7.82

It may take a day or so for new Firefox vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Mozilla Firefox Security Vulnerabilities

Firefox 154/153.1 memcorr flaw (CVE-2026-84144)
CVE-2026-84144 7.5 - High - September 01, 2026

Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Buffer Overflow

Firefox <155 memory corruption CVE-2026-84143
CVE-2026-84143 9.8 - Critical - September 01, 2026

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Information Disclosure

Memory Corruption in Firefox 154 (CVE-2026-84142)
CVE-2026-84142 9.8 - Critical - September 01, 2026

Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Information Disclosure

Firefox Integer Overflow in ImageLib (Graphics) Before v155
CVE-2026-84141 9.8 - Critical - September 01, 2026

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Integer Overflow or Wraparound

Firefox 153.x+ Site Isolation DOM Navigation Vulnerability (CVE-2026-84140)
CVE-2026-84140 9.8 - Critical - September 01, 2026

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Origin Validation Error

Firefox DOM Events clickjacking before v155
CVE-2026-84139 9.8 - Critical - September 01, 2026

Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Clickjacking

DoS in Firefox PDF Viewer (CVE-2026-84138)
CVE-2026-84138 7.5 - High - September 01, 2026

Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Resource Exhaustion

Firefox DOM Spoofing in Core & HTML Fixed in 155
CVE-2026-84137 9.8 - Critical - September 01, 2026

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

User Interface (UI) Misrepresentation of Critical Information

Firefox DOM Navigation Component Vulnerability (Fixed in 155)
CVE-2026-84136 9.8 - Critical - September 01, 2026

Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Information Disclosure

Mozilla Firefox Focus Android CVE-2026-84135: Other Issue
CVE-2026-84135 9.8 - Critical - September 01, 2026

Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

Information Disclosure

Firefox 155+ Profile Backup component flaw (CVE-2026-84134)
CVE-2026-84134 9.8 - Critical - September 01, 2026

Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Information Disclosure

Firefox DOM Push Subscriptions site isolation flaw before v155
CVE-2026-84133 9.8 - Critical - September 01, 2026

Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Origin Validation Error

Firefox <155 Info Disclosure in Networking HTTP Component
CVE-2026-84132 7.5 - High - September 01, 2026

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Information Disclosure

Firefox WebGPU Info Disclosure (before v155)
CVE-2026-84130 7.5 - High - September 01, 2026

Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Information Disclosure

Firefox SiteIsolation DOM Navigation Bug Fixed V155 ESR153.2
CVE-2026-84129 9.8 - Critical - September 01, 2026

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Origin Validation Error

Firefox Privilege Escalation via WebDriver BiDi
CVE-2026-84128 8.8 - High - September 01, 2026

Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Authorization

Firefox Android WebExtensions Info Disclosure
CVE-2026-84127 4.3 - Medium - September 01, 2026

Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.

Information Disclosure

Firefox Grid Layout Boundary Condition Vulnerability (CVE-2026-84126)
CVE-2026-84126 4.3 - Medium - September 01, 2026

Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Classic Buffer Overflow

Use-After-Free in Firefox Core & HTML DOM Component <155
CVE-2026-84125 5.4 - Medium - September 01, 2026

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Dangling pointer

Use-after-free in Firefox DOM: Core & HTML (before 155)
CVE-2026-84124 5.4 - Medium - September 01, 2026

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Dangling pointer

Firefox Privilege Escalation via WebGPU Use-After-Free (before 155)
CVE-2026-84123 8.8 - High - September 01, 2026

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Dangling pointer

UAF in Firefox Media Component (fixed 155/ESR 140.15/153.2)
CVE-2026-84122 5.4 - Medium - September 01, 2026

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Dangling pointer

Use-after-Free in Firefox 155 JS GC component (before 155)
CVE-2026-84118 5.4 - Medium - September 01, 2026

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Dangling pointer

Privilege Escalation in Firefox Android 155+
CVE-2026-84117 8.8 - High - September 01, 2026

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

Authorization

Firefox 154 ESR 115.39 Memory Corruption Vulnerability
CVE-2026-84145 7.5 - High - September 01, 2026

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Buffer Overflow

Firefox Priv Esc Prt Err in Graphics Comp (<155, ESR<115.40, ESR<140.15, ESR<153.2)
CVE-2026-84131 8.8 - High - September 01, 2026

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Release of Invalid Pointer or Reference

Firefox Sandbox escape via DOM UAF (fixed in 155)
CVE-2026-84121 9.6 - Critical - September 01, 2026

Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Dangling pointer

Use-after-free in Audio/Video component of Firefox <155 (ESR 115.40)
CVE-2026-84120 5.4 - Medium - September 01, 2026

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Dangling pointer

Firefox Sandbox Escape UAF in DOM Navigation Component
CVE-2026-84119 9.6 - Critical - September 01, 2026

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Dangling pointer

Firefox iOS 155.0: Cross-Origin Popup Navigation Stall
CVE-2026-81267 5.4 - Medium - August 31, 2026

A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.

User Interface (UI) Misrepresentation of Critical Information

Memory corruption bugs in Firefox 153
CVE-2026-74989 9.8 - Critical - August 18, 2026

Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

Buffer Overflow

Firefox ESR 153.0 Memory Corruption Vulnerability (fixed in 153.1)
CVE-2026-74988 9.8 - Critical - August 18, 2026

Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Buffer Overflow

DoS in Firefox Widget component before 154/ESR153.1
CVE-2026-74982 7.5 - High - August 18, 2026

Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Resource Exhaustion

Race Condition in JS Engine, Firefox <154, fixed v154
CVE-2026-74984 6.8 - Medium - August 18, 2026

Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Race Condition

Firefox 154 ESR 153.1 Fixed PrivEsc in Enterprise Policies
CVE-2026-74985 9.8 - Critical - August 18, 2026

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Improper Privilege Management

CSS Parsing Component Site Isolation Flaw Fixed in Firefox 154 & ESR 153.1
CVE-2026-74986 9.1 - Critical - August 18, 2026

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Information Disclosure

Site Isolation Vulnerability in Web Codecs (Firefox <154, Thunderbird <154)
CVE-2026-74981 8.1 - High - August 18, 2026

Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Origin Validation Error

Clickjacking Vulnerability in Firefox Android Downloads Component
CVE-2026-74980 6.5 - Medium - August 18, 2026

Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

Clickjacking

Mitigation bypass in Addons Manager (Firefox 154, ESR 153.1, Thunderbird 154)
CVE-2026-74979 9.8 - Critical - August 18, 2026

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Authorization

Clickjacking in Firefox/Thunderbird widget component before v154
CVE-2026-74978 8.1 - High - August 18, 2026

Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Clickjacking

Site Isolation Flaw in WebRender of Firefox/Thunderbird (v<154)
CVE-2026-74968 5.4 - Medium - August 18, 2026

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Origin Validation Error

Site isolation flaw in Firefox Graphics before v154
CVE-2026-74970 5.4 - Medium - August 18, 2026

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Origin Validation Error

Firefox & Thunderbird Graphics INT Overflow CVE-2026-74977 Fixed 154
CVE-2026-74977 7.5 - High - August 18, 2026

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Integer Overflow or Wraparound

Firefox Android Downloads Spoofing Vulnerability
CVE-2026-74975 5.4 - Medium - August 18, 2026

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

User Interface (UI) Misrepresentation of Critical Information

Firefox 154: Information Disclosure in Form Autofill
CVE-2026-74966 7.5 - High - August 18, 2026

Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Privacy violation

Web Audio side-channel in Firefox 154, Thunderbird 154
CVE-2026-74961 9.1 - Critical - August 18, 2026

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Side Channel Attack

CVE-2026-74958: WebRTC Info Disclosure before Firefox+Thunderbird 154
CVE-2026-74958 7.5 - High - August 18, 2026

Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Clickjacking

Same-Origin Policy Bypass in Service Workers (Firefox <154, Thunderbird <154)
CVE-2026-74956 9.1 - Critical - August 18, 2026

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Object Type Confusion

Mozilla Firefox AppUpd PrivEsc via Application Update Vulnerability
CVE-2026-74952 8.8 - High - August 18, 2026

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 153.2, and Thunderbird 153.2.

Improper Privilege Management

Privilege Escalation via Request Handling in Firefox 154 & Thunderbird 154
CVE-2026-74955 8.8 - High - August 18, 2026

Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Improper Privilege Management

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Mozilla Firefox or by Mozilla? Click the Watch button to subscribe.

Mozilla
Vendor

Mozilla Firefox
Open source web browser

subscribe