Mozilla Firefox Open source web browser
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Mozilla Firefox.
Recent Mozilla Firefox Security Advisories
| Advisory | Title | Published |
|---|---|---|
| mfsa2026-69 | Security Vulnerabilities fixed in Firefox ESR 115.38 mfsa2026-69 | July 21, 2026 |
| mfsa2026-68 | Security Vulnerabilities fixed in Firefox 153 mfsa2026-68 | July 21, 2026 |
| mfsa2026-70 | Security Vulnerabilities fixed in Firefox ESR 140.13 mfsa2026-70 | July 21, 2026 |
| mfsa2026-67 | Security Vulnerabilities fixed in Firefox 152.0.6 mfsa2026-67 | July 14, 2026 |
| mfsa2026-66 | Security Vulnerabilities fixed in Firefox for iOS 152.4 mfsa2026-66 | July 13, 2026 |
| mfsa2026-65 | Security Vulnerabilities fixed in Firefox for iOS 152.3 mfsa2026-65 | July 5, 2026 |
| mfsa2026-62 | Security Vulnerabilities fixed in Firefox 152.0.4 mfsa2026-62 | June 30, 2026 |
| mfsa2026-57 | Security Vulnerabilities fixed in Firefox 152 mfsa2026-57 | June 16, 2026 |
| mfsa2026-58 | Security Vulnerabilities fixed in Firefox ESR 140.12 mfsa2026-58 | June 16, 2026 |
| mfsa2026-59 | Security Vulnerabilities fixed in Firefox ESR 115.37 mfsa2026-59 | June 16, 2026 |
Known Exploited Mozilla Firefox Vulnerabilities
The following Mozilla Firefox vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. CVE-2024-9680 Exploit Probability: 23.2% |
October 15, 2024 |
| Mozilla Firefox Security Feature Bypass Vulnerability |
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. CVE-2015-4495 Exploit Probability: 70.2% |
May 25, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. CVE-2022-26486 Exploit Probability: 2.3% |
March 7, 2022 |
| Mozilla Firefox Use-After-Free Vulnerability |
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. CVE-2022-26485 Exploit Probability: 14.3% |
March 7, 2022 |
| Mozilla Firefox Information Disclosure Vulnerability |
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. CVE-2013-1675 Exploit Probability: 6.7% |
March 3, 2022 |
The vulnerability CVE-2015-4495: Mozilla Firefox Security Feature Bypass Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited Mozilla Firefox vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
EOL Dates
Ensure that you are using a supported version of Mozilla Firefox. Here are some end of life, and end of support dates for Mozilla Firefox.
| Release | EOL Date | Status |
|---|---|---|
| 153 | - |
Active
|
| 152 | July 21, 2026 |
EOL
Mozilla Firefox 152 became EOL in 2026. |
| 151 | June 16, 2026 |
EOL
Mozilla Firefox 151 became EOL in 2026. |
| 150 | May 18, 2026 |
EOL
Mozilla Firefox 150 became EOL in 2026. |
| 149 | April 21, 2026 |
EOL
Mozilla Firefox 149 became EOL in 2026. |
| 148 | March 24, 2026 |
EOL
Mozilla Firefox 148 became EOL in 2026. |
| 147 | February 24, 2026 |
EOL
Mozilla Firefox 147 became EOL in 2026. |
| 146 | January 13, 2026 |
EOL
Mozilla Firefox 146 became EOL in 2026. |
| 145 | December 9, 2025 |
EOL
Mozilla Firefox 145 became EOL in 2025. |
| 144 | November 11, 2025 |
EOL
Mozilla Firefox 144 became EOL in 2025. |
| 143 | October 14, 2025 |
EOL
Mozilla Firefox 143 became EOL in 2025. |
| 142 | September 16, 2025 |
EOL
Mozilla Firefox 142 became EOL in 2025. |
| 141 | August 19, 2025 |
EOL
Mozilla Firefox 141 became EOL in 2025. |
| 140 | September 29, 2026 |
EOL This Year
Mozilla Firefox 140 will become EOL this year, in September 2026. |
| 139 | June 24, 2025 |
EOL
Mozilla Firefox 139 became EOL in 2025. |
| 138 | May 27, 2025 |
EOL
Mozilla Firefox 138 became EOL in 2025. |
| 137 | April 29, 2025 |
EOL
Mozilla Firefox 137 became EOL in 2025. |
| 136 | April 1, 2025 |
EOL
Mozilla Firefox 136 became EOL in 2025. |
| 135 | March 4, 2025 |
EOL
Mozilla Firefox 135 became EOL in 2025. |
| 134 | February 4, 2025 |
EOL
Mozilla Firefox 134 became EOL in 2025. |
By the Year
In 2026 there have been 331 vulnerabilities in Mozilla Firefox with an average score of 7.8 out of ten. Last year, in 2025 Firefox had 189 security vulnerabilities published. That is, 142 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.23.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 331 | 7.77 |
| 2025 | 189 | 7.54 |
| 2024 | 190 | 7.15 |
| 2023 | 180 | 7.38 |
| 2022 | 159 | 7.44 |
| 2021 | 123 | 7.13 |
| 2020 | 148 | 7.27 |
| 2019 | 121 | 7.44 |
| 2018 | 312 | 7.82 |
It may take a day or so for new Firefox vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Mozilla Firefox Security Vulnerabilities
Firefox ESR Memory Safety Bug (ESR 115.37/140.12) Fixed in 115.38/140.13
CVE-2026-16361
9.8 - Critical
- July 21, 2026
Memory safety bugs present in Thunderbird ESR 140.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
Buffer Overflow
Memory Safety Bugs in Firefox 115.37-140.12 & 152 (fixed 153 ESR)
CVE-2026-16360
9.8 - Critical
- July 21, 2026
Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Buffer Overflow
Memory Safety Bugs in Firefox 152 & ESR 140.12 (fixed 153/140.13)
CVE-2026-16412
9.8 - Critical
- July 21, 2026
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Buffer Overflow
Firefox JIT Miscompilation in JS Engine (CVE-2026-16410)
CVE-2026-16410
9.8 - Critical
- July 21, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Object Type Confusion
Firefox 152 Memory Safety Bugs Causing Arbitrary Code Exec
CVE-2026-16411
9.8 - Critical
- July 21, 2026
Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Buffer Overflow
Firefox 153: Invalid Pointer in PSM Component
CVE-2026-16409
7.5 - High
- July 21, 2026
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Access of Uninitialized Pointer
Mozilla Firefox: Integer Overflow in Audio/Video Playback Component
CVE-2026-16408
9.8 - Critical
- July 21, 2026
Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Integer Overflow or Wraparound
Firefox: Service Workers DOM Mitigation Bypass (CVE-2026-16407)
CVE-2026-16407
9.8 - Critical
- July 21, 2026
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Protection Mechanism Failure
Mitigation Bypass in Firefox Networking Component
CVE-2026-16406
9.1 - Critical
- July 21, 2026
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Protection Mechanism Failure
Info disclosure in Firefox WebSockets before v153/ESR140.13
CVE-2026-16405
7.5 - High
- July 21, 2026
Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Information Disclosure
Spoofing Vulnerability CVE-2026-16404 in Firefox Android
CVE-2026-16404
7.4 - High
- July 21, 2026
Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.
Authentication Bypass by Spoofing
Address Bar Spoofing Issue in Firefox
CVE-2026-16403
6.5 - Medium
- July 21, 2026
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
User Interface (UI) Misrepresentation of Critical Information
Firefox Integer Overflow: ImageLib Component (Fixed in v153)
CVE-2026-16402
9.8 - Critical
- July 21, 2026
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Integer Overflow or Wraparound
Firefox DLP Component Privilege Escalation (CVE-2026-16401)
CVE-2026-16401
9.8 - Critical
- July 21, 2026
Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Improper Privilege Management
Firefox DOM Security Component Info Disclosure (CVE-2026-16400)
CVE-2026-16400
7.5 - High
- July 21, 2026
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Information Disclosure
Firefox DOM Navigation Site Isolation Vulnerability
CVE-2026-16399
7.5 - High
- July 21, 2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Origin Validation Error
Firefox Graphics Site Isolation Flaw
CVE-2026-16398
7.5 - High
- July 21, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Origin Validation Error
Firefox Android WebExt Clickjacking via UI Manipulation
CVE-2026-16397
6.5 - Medium
- July 21, 2026
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
Clickjacking
Firefox WebExtensions Privilege Escalation Fixed in v153 & ESR 140.13
CVE-2026-16396
9.8 - Critical
- July 21, 2026
Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Improper Privilege Management
Integer Overflow in Firefox AV Component
CVE-2026-16395
9.8 - Critical
- July 21, 2026
Integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Integer Overflow or Wraparound
Firefox DOM Mitigation Bypass in Security Component
CVE-2026-16394
9.1 - Critical
- July 21, 2026
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Protection Mechanism Failure
Firefox GMP Boundary Condition Vulnerability Fixed in 153/115.38/140.13
CVE-2026-16359
9.1 - Critical
- July 21, 2026
Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Buffer Overflow
Firefox WebGPU Boundary Condition Vulnerability
CVE-2026-16393
9.1 - Critical
- July 21, 2026
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Buffer Overflow
Firefox JIT Engine Miscompilation CVE-2026-16392
CVE-2026-16392
- July 21, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Mozilla Firefox <153 ESR 140.13: IndexedDB Info Disclosure
CVE-2026-16391
7.5 - High
- July 21, 2026
Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Information Disclosure
Firefox Mitigation Bypass in Enterprise Policies (before 153 / ESR 140.13)
CVE-2026-16390
9.1 - Critical
- July 21, 2026
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Protection Mechanism Failure
Integer overflow in Mozilla NSS Libraries
CVE-2026-16389
9.8 - Critical
- July 21, 2026
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Integer Overflow or Wraparound
Firefox Sandbox Escape: DOM Networking Component
CVE-2026-16388
9.8 - Critical
- July 21, 2026
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Protection Mechanism Failure
Site Isolation Issue in Firefox Networking Component (fixed in 153/140.13)
CVE-2026-16387
9.8 - Critical
- July 21, 2026
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Origin Validation Error
CVE-2026-16386: WebGPU Uninitialized Memory Disclosure in Firefox
CVE-2026-16386
7.5 - High
- July 21, 2026
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Use of Uninitialized Resource
Info Disclosure via Uninit Mem in Firefox WebGPU
CVE-2026-16385
7.5 - High
- July 21, 2026
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Use of Uninitialized Resource
Firefox WebGPU Uninitialized Memory Disclosure
CVE-2026-16384
7.5 - High
- July 21, 2026
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Use of Uninitialized Resource
Mitigation Bypass in Firefox DOM Networking (before 153/140.13)
CVE-2026-16383
9.8 - Critical
- July 21, 2026
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Protection Mechanism Failure
Firefox service workers mitigation bypass (CVE-2026-16382)
CVE-2026-16382
9.8 - Critical
- July 21, 2026
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Protection Mechanism Failure
Firefox Same-Op Policy Bypass in Networking:DNS (pre-153/140.13)
CVE-2026-16381
9.1 - Critical
- July 21, 2026
Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Origin Validation Error
Mitigation bypass in Firefox Networking component
CVE-2026-16380
9.1 - Critical
- July 21, 2026
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Protection Mechanism Failure
CVE-2026-16358: FireFox WebRender Site Isolation Fix 153
CVE-2026-16358
9.8 - Critical
- July 21, 2026
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Origin Validation Error
Privilege Escalation via DOM in Firefox 153/ESR 140.13
CVE-2026-16379
9.8 - Critical
- July 21, 2026
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Improper Privilege Management
Firefox DOM Copy&Paste/Drag&Drop Issue
CVE-2026-16378
7.5 - High
- July 21, 2026
Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Improper Input Validation
Mitigation Bypass in Firefox PDF Viewer (before v153, ESR 140.13)
CVE-2026-16377
9.8 - Critical
- July 21, 2026
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Protection Mechanism Failure
DoS via WebGPU in Firefox
CVE-2026-16376
7.5 - High
- July 21, 2026
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Resource Exhaustion
Site Isolation Flaw in Firefox HTTP Network (fixed 153, ESR140.13)
CVE-2026-16375
9.8 - Critical
- July 21, 2026
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Origin Validation Error
Info Disclosure in Firefox DevTools Framework (153)
CVE-2026-16374
7.5 - High
- July 21, 2026
Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Information Disclosure
Firefox Android Info Disclosure Privacy Comp.
CVE-2026-16373
7.5 - High
- July 21, 2026
Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
Information Disclosure
Privilege Escalation in Firefox DOM Content Process Component
CVE-2026-16372
9.8 - Critical
- July 21, 2026
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Improper Privilege Management
Firefox 153 Priv Esc in DOM Nav Component
CVE-2026-16371
9.8 - Critical
- July 21, 2026
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Improper Privilege Management
Firefox Networking Component DOM Mitigation Bypass
CVE-2026-16370
9.1 - Critical
- July 21, 2026
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Protection Mechanism Failure
Boundary Cond. Bug in Firefox Graphics (Fixed before v153)
CVE-2026-16357
9.8 - Critical
- July 21, 2026
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Buffer Overflow
Firefox UAF Sandbox Escape in Disability Access APIs (pre153)
CVE-2026-16356
9.8 - Critical
- July 21, 2026
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Dangling pointer
Firefox JavaScript Engine JIT Miscompilation before v153
CVE-2026-16355
9.8 - Critical
- July 21, 2026
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Object Type Confusion
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Mozilla Firefox or by Mozilla? Click the Watch button to subscribe.