SB20260731180 - Anolis OS update for thunderbird



SB20260731180 - Anolis OS update for thunderbird

Published: July 31, 2026

Security Bulletin ID SB20260731180
CSH Severity
High
Patch available
YES
Number of vulnerabilities 206
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 59% Medium 29% Low 12%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 206 vulnerabilities.


1) Use-after-free (CVE-ID: CVE-2025-10527)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in Graphics: Canvas2D component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


2) Buffer overflow (CVE-ID: CVE-2025-10528)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in Graphics: Canvas2D component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


3) Security features bypass (CVE-ID: CVE-2025-10529)

CWE-ID: CWE-254 - Security Features

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in the Layout component. A remote attacker can bypass same-origin policy and gain unauthorized access to data outside of the current domain. 


4) Out-of-bounds read (CVE-ID: CVE-2025-10532)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in the JavaScript: GC component. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger an out-of-bounds read error and read contents of memory on the system.


5) Integer overflow (CVE-ID: CVE-2025-10533)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the SVG component. A remote attacker can trick the victim into visiting a specially crafted website, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


6) Information disclosure (CVE-ID: CVE-2025-10536)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the Networking: Cache component. A remote attacker can gain unauthorized access to sensitive information on the system.


7) Buffer overflow (CVE-ID: CVE-2025-10537)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


8) Use-after-free (CVE-ID: CVE-2025-11708)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in MediaTrackGraphImpl::GetInstance(). A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


9) Out-of-bounds write (CVE-ID: CVE-2025-11709)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing WebGL textures. A remote attacker can create a specially crafted website, trick the victim into opening it using the affected software, trigger an out-of-bounds write and execute arbitrary code on the target system.


10) Information disclosure (CVE-ID: CVE-2025-11710)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A compromised web process using malicious IPC messages can cause the privileged browser process to reveal blocks of its memory to the compromised process.


11) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-11711)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to application does not properly impose security restrictions, which allows an malicious web application to modify JavaScript Object properties that were supposed to be non-writable. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.


12) Protection mechanism failure (CVE-ID: CVE-2025-11712)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. A malicious page can use the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This can lead to an XSS on a site that unsafely serves files without a content-type header.


13) Buffer overflow (CVE-ID: CVE-2025-11714)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


14) Buffer overflow (CVE-ID: CVE-2025-11715)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


15) Race condition (CVE-ID: CVE-2025-13012)

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in the Graphics component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.


16) Protection Mechanism Failure (CVE-ID: CVE-2025-13013)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the DOM: Core & HTML component. An attacker can bypass implemented security restrictions.


17) Use-after-free (CVE-ID: CVE-2025-13014)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a use-after-free error in the Audio/Video component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser. 


18) Spoofing attack (CVE-ID: CVE-2025-13015)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can perform spoofing attack.


19) Buffer overflow (CVE-ID: CVE-2025-13016)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the JavaScript: WebAssembly component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


20) Protection Mechanism Failure (CVE-ID: CVE-2025-13017)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the DOM: Notifications component. An attacker can bypass implemented security restrictions.


21) Protection Mechanism Failure (CVE-ID: CVE-2025-13018)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the DOM: Security component. An attacker can bypass implemented security restrictions.


22) Protection Mechanism Failure (CVE-ID: CVE-2025-13019)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the DOM: Workers component. An attacker can bypass implemented security restrictions.


23) Use-after-free (CVE-ID: CVE-2025-13020)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a use-after-free error in the WebRTC: Audio/Video component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser.


24) Use-after-free (CVE-ID: CVE-2025-14321)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the the WebRTC Signaling component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


25) Buffer overflow (CVE-ID: CVE-2025-14322)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape sandbox restrictions.

The vulnerability exists due to a boundary error in the Graphics CanvasWebGL component. A remote attacker can trick the victim into visiting a specially craft6ed website, trigger memory corruption and escape sandbox restrictions.


26) Improper privilege management (CVE-ID: CVE-2025-14323)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper privilege management in the DOM Notifications component. A remote attacker can trick the victim into visiting a specially crafted website and bypass implemented security restrictions. 


27) Input validation error (CVE-ID: CVE-2025-14324)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due JIT miscompilation in the JavaScript Engine JIT component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system. 


28) Input validation error (CVE-ID: CVE-2025-14325)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due JIT miscompilation in the JavaScript Engine JIT component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system. 


29) Spoofing attack (CVE-ID: CVE-2025-14327)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data in the Downloads Panel component. A remote attacker can perform a spoofing attack. 


30) Improper privilege management (CVE-ID: CVE-2025-14328)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper privilege management in the Netmonitor component. A remote attacker can trick the victim into visiting a specially crafted website and bypass implemented security restrictions. 


31) Improper privilege management (CVE-ID: CVE-2025-14329)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper privilege management in the Netmonitor component. A remote attacker can trick the victim into visiting a specially crafted website and bypass implemented security restrictions. 


32) Input validation error (CVE-ID: CVE-2025-14330)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due JIT miscompilation in the JavaScript Engine JIT component. A remote attacker can trick the victim into visiting a specially crafted website and bypass implemented security restrictions.


33) Protection mechanism failure (CVE-ID: CVE-2025-14331)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the Request Handling component. A remote attacker can trick the victim into visiting a specially crafted website and bypass Same-Origin policy.  


34) Buffer overflow (CVE-ID: CVE-2025-14333)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


35) Protection mechanism failure (CVE-ID: CVE-2026-0877)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. An attacker can bypass implemented DOM security restrictions and execute arbitrary JavaScript code.


36) Buffer overflow (CVE-ID: CVE-2026-0878)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the in the Graphics: CanvasWebGL component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


37) Buffer overflow (CVE-ID: CVE-2026-0879)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the Graphics component. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


38) Integer overflow (CVE-ID: CVE-2026-0880)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the Graphics component. A remote attacker can trick the victim into visiting a specially crafted website, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


39) Use-after-free (CVE-ID: CVE-2026-0882)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the IPC component. A remote attacker can trick the victim into visiting a specially crafted web page and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


40) Information disclosure (CVE-ID: CVE-2026-0883)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the Networking component. A remote attacker can gain unauthorized access to sensitive information on the system.


41) Use-after-free (CVE-ID: CVE-2026-0884)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a use-after-free error in the JavaScript Engine component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser.


42) Use-after-free (CVE-ID: CVE-2026-0885)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a use-after-free error in the JavaScript: GC component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser.


43) Buffer overflow (CVE-ID: CVE-2026-0886)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the Graphics component. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


44) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-0887)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform clickjacking attacks.

The vulnerability exists due to an error in the PDF Viewer. A remote attacker can trick the victim into opening a specially crafted URL and gain access to sensitive information or perform clickjacking attack.


45) Spoofing attack (CVE-ID: CVE-2026-0890)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data in the DOM: Copy & Paste and Drag & Drop component. A remote attacker can spoof page content.


46) Buffer overflow (CVE-ID: CVE-2026-0891)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


47) Improper access control (CVE-ID: CVE-2026-12289)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Graphics: WebRender component when rendering web content. A remote attacker can trigger the vulnerable component to escalate privileges.


48) Buffer overflow (CVE-ID: CVE-2026-12290)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in Firefox ESR when processing crafted content. A remote attacker can trigger the memory safety bug to execute arbitrary code.


49) Use-after-free (CVE-ID: CVE-2026-12291)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Networking: HTTP component when handling HTTP content. A remote attacker can send crafted content to execute arbitrary code.


50) Out-of-bounds write (CVE-ID: CVE-2026-12292)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in the Web Audio component when processing audio content. A remote attacker can trigger the vulnerable behavior to execute arbitrary code.


51) Improper access control (CVE-ID: CVE-2026-12294)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper access control in the DOM: Workers component when processing worker content. A remote attacker can trigger the vulnerable component to escape the sandbox.


52) Improper access control (CVE-ID: CVE-2026-12295)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper access control in the DOM: Navigation component when processing navigation operations. A remote attacker can trigger the vulnerable component to escape the sandbox.


53) Improper access control (CVE-ID: CVE-2026-12296)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper access control in the Security: Process Sandboxing component when enforcing sandbox restrictions. A remote attacker can trigger the vulnerable behavior to escape the sandbox.


54) Buffer overflow (CVE-ID: CVE-2026-12297)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions in the Networking component when processing network data. A remote attacker can trigger the vulnerable component to escape the sandbox.


55) Buffer overflow (CVE-ID: CVE-2026-12298)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to execute arbitrary code.


56) Incorrect calculation (CVE-ID: CVE-2026-12299)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to JIT miscompilation in the DOM: Core & HTML component when executing script. A remote attacker can supply crafted script to execute arbitrary code.


57) Protection Mechanism Failure (CVE-ID: CVE-2026-12302)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the DOM: Security component when enforcing security restrictions. A remote attacker can trigger the vulnerable component to bypass a security mitigation.


58) Improper access control (CVE-ID: CVE-2026-12304)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass the same-origin policy.

The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookies. A remote attacker can trigger the vulnerable behavior to bypass the same-origin policy.


59) Buffer overflow (CVE-ID: CVE-2026-12305)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


60) Buffer overflow (CVE-ID: CVE-2026-12306)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


61) Buffer overflow (CVE-ID: CVE-2026-12307)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


62) Buffer overflow (CVE-ID: CVE-2026-12308)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


63) Buffer overflow (CVE-ID: CVE-2026-12309)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


64) Buffer overflow (CVE-ID: CVE-2026-12310)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


65) Improper access control (CVE-ID: CVE-2026-12311)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to disclose sensitive information and escape the sandbox.

The vulnerability exists due to improper access control in the Security: Process Sandboxing component when enforcing sandbox restrictions. A remote attacker can trigger the vulnerable behavior to disclose sensitive information and escape the sandbox.


66) Buffer overflow (CVE-ID: CVE-2026-12312)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


67) Improper access control (CVE-ID: CVE-2026-12313)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to disclose sensitive information and escape the sandbox.

The vulnerability exists due to improper access control in the Security: Process Sandboxing component when enforcing sandbox restrictions. A remote attacker can trigger the vulnerable behavior to disclose sensitive information and escape the sandbox.


68) Buffer overflow (CVE-ID: CVE-2026-12314)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


69) Protection Mechanism Failure (CVE-ID: CVE-2026-12315)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the DOM: Security component when enforcing security restrictions. A remote attacker can trigger the vulnerable behavior to bypass a security mitigation.


70) Out-of-bounds read (CVE-ID: CVE-2026-12324)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in the Graphics: CanvasWebGL component when rendering WebGL content. A remote attacker can trigger the vulnerable behavior to cause a denial of service.


71) Input validation error (CVE-ID: CVE-2026-12325)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in the Graphics: ImageLib component when parsing image content. A remote attacker can supply crafted image content to cause a denial of service.


72) Buffer overflow (CVE-ID: CVE-2026-12327)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple unspecified components when parsing input. A remote attacker can trigger the vulnerable behavior to execute arbitrary code.

Some of the bugs showed evidence of memory corruption.


73) Buffer overflow (CVE-ID: CVE-2026-12328)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in Firefox ESR when processing crafted content. A remote attacker can trigger the memory safety bugs to execute arbitrary code.

Some of the bugs showed evidence of memory corruption.


74) Buffer overflow (CVE-ID: CVE-2026-12329)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in an unspecified component when parsing input. A remote attacker can trigger the vulnerable behavior to execute arbitrary code.


75) Buffer overflow (CVE-ID: CVE-2026-12330)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the Internationalization component when parsing input. A remote attacker can supply crafted input to cause a denial of service.


76) Heap-based buffer overflow (CVE-ID: CVE-2026-2447)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in libvpx. A remote attacker can trick the victim into visiting a specially crafted webpage, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


77) Buffer overflow (CVE-ID: CVE-2026-2757)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in WebRTC: Audio/Video component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


78) Use-after-free (CVE-ID: CVE-2026-2758)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in JavaScript: GC component. A remote attacker can trick the victim into visiting a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.



79) Buffer overflow (CVE-ID: CVE-2026-2759)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in the Graphics: ImageLib component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.


80) Buffer overflow (CVE-ID: CVE-2026-2760)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in in the Graphics: WebRender component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption to bypass sandbox restrictions and execute arbitrary code on the target system.


81) Buffer overflow (CVE-ID: CVE-2026-2761)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content in in the Graphics: WebRender component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption to bypass sandbox restrictions and execute arbitrary code on the target system.


82) Integer overflow (CVE-ID: CVE-2026-2762)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the JavaScript: Standard Library component. A remote attacker can trick the victim into visiting a specially crafted website, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


83) Use-after-free (CVE-ID: CVE-2026-2763)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the JavaScript Engine component. A remote attacker can trick the victim into visiting a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.



84) Use-after-free (CVE-ID: CVE-2026-2764)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the JavaScript Engine: JIT component. A remote attacker can trick the victim into visiting a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.



85) Use-after-free (CVE-ID: CVE-2026-2765)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the JavaScript Engine component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.


86) Use-after-free (CVE-ID: CVE-2026-2766)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the JavaScript Engine: JIT component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.


87) Use-after-free (CVE-ID: CVE-2026-2767)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the JavaScript: WebAssembly component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.


88) Protection mechanism failure (CVE-ID: CVE-2026-2768)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient implementation of security measures in the Storage: IndexedDB component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.


89) Use-after-free (CVE-ID: CVE-2026-2769)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the Storage: IndexedDB component. A remote attacker can trick the victim into visiting a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.



90) Use-after-free (CVE-ID: CVE-2026-2770)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the DOM: Bindings (WebIDL) component. A remote attacker can trick the victim into visiting a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.



91) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-2771)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to improper input validation in the DOM: Core & HTML component. A remote attacker can execute arbitrary JavaScript code in the browser leading to a system compromise. 


92) Use-after-free (CVE-ID: CVE-2026-2772)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in the Audio/Video: Playback component. A remote attacker can trick the victim into visiting a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.



93) Buffer overflow (CVE-ID: CVE-2026-2773)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the Web Audio component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.


94) Integer overflow (CVE-ID: CVE-2026-2774)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the Audio/Video component. A remote attacker can trick the victim into visiting a specially crafted website, trigger an integer overflow and execute arbitrary code on the target system.


95) Protection mechanism failure (CVE-ID: CVE-2026-2775)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the DOM: HTML Parser component. An attacker can trick the victim into visiting a specially crafted website and compromise the affected system.


96) Buffer overflow (CVE-ID: CVE-2026-2776)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the Telemetry component in External Software. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption to bypass sandbox restrictions and execute arbitrary code on the target system.


97) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-2777)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to application does not properly impose security restrictions in the Messaging System component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.


98) Buffer overflow (CVE-ID: CVE-2026-2778)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML code in the DOM: Core & HTML component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.


99) Buffer overflow (CVE-ID: CVE-2026-2779)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a boundary error when processing HTML content in the Networking: JAR component. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and crash the browser.


100) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-2780)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions in the Netmonitor component. A remote attacker can escalate privileges on the system.


101) Integer overflow (CVE-ID: CVE-2026-2781)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to integer overflow in the Libraries component in NSS. A remote attacker can trick the victim into visiting a specially crafted website, trigger an integer overflow and crash the browser.


102) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2026-2782)

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions in the Netmonitor component. A remote attacker can escalate privileges on the system.


103) Information disclosure (CVE-ID: CVE-2026-2783)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component. A remote attacker can gain unauthorized access to sensitive information.


104) Protection mechanism failure (CVE-ID: CVE-2026-2784)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the DOM: Security component. An attacker can bypass implemented security restrictions.


105) NULL pointer dereference (CVE-ID: CVE-2026-2785)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the JavaScript Engine component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser. 


106) Use-after-free (CVE-ID: CVE-2026-2786)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a use-after-free error in the JavaScript Engine component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser. 


107) Use-after-free (CVE-ID: CVE-2026-2787)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a use-after-free error in the DOM: Window and Location component. A remote attacker can trick the victim into visiting a specially crafted webpage and crash the browser. 


108) Buffer overflow (CVE-ID: CVE-2026-2788)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to crash the browser

The vulnerability exists due to a boundary error in the Audio/Video: GMP component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser.


109) Use-after-free (CVE-ID: CVE-2026-2789)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to crash the browser.

The vulnerability exists due to a use-after-free error in the Graphics: ImageLib component. A remote attacker can trick the victim into visiting a specially crafted webpage and crash the browser. 


110) Protection mechanism failure (CVE-ID: CVE-2026-2790)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the Networking: JAR component. An attacker can bypass same-origin policy. 


111) Protection mechanism failure (CVE-ID: CVE-2026-2791)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the Networking: Cache component. An attacker can bypass implemented security restrictions.


112) Buffer overflow (CVE-ID: CVE-2026-2792)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.


113) Buffer overflow (CVE-ID: CVE-2026-2793)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.


114) Use-after-free (CVE-ID: CVE-2026-33416)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in png_set_tRNS and png_set_PLTE when processing a crafted PNG file and subsequent decoding after png_free_data() or repeated setter calls. A remote attacker can supply a specially crafted PNG file to execute arbitrary code.

User interaction is required to open or process the crafted PNG file, and exploitation affects applications that free PNG data between png_read_info() and png_read_update_info().


115) Out-of-bounds read (CVE-ID: CVE-2026-33636)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service, disclose sensitive information, and corrupt memory.

The vulnerability exists due to out-of-bounds read and out-of-bounds write in the ARM/AArch64 Neon palette expansion path when decoding a crafted paletted PNG image with palette expansion enabled. A remote attacker can supply a specially crafted PNG image to cause a denial of service, disclose sensitive information, and corrupt memory.

Only builds targeting ARM/AArch64 with Neon enabled are affected. The issue is triggered for palette-based images during palette expansion, with the RGBA path requiring a tRNS chunk and the RGB path requiring no tRNS chunk. User interaction is required to open or process the crafted image.


116) Multiple interpretations of UI input (CVE-ID: CVE-2026-3889)

CWE-ID: CWE-450 - Multiple Interpretations of UI Input

CVSSv4: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to improper implementation of UI. A remote attacker can send a specially crafted email to the victim and perform spoofing attack. 


117) Out-of-bounds read (CVE-ID: CVE-2026-4371)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition when reading responses from the IMAP server. A remote attacker with control over a malicious IMAP server can send specially crafted responses to the email client, trigger an out-of-bounds read error and read contents of memory on the system.


118) Use After Free (CVE-ID: CVE-2026-4684)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a race condition, use-after-free in the Graphics: WebRender component when processing graphical content. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.

Exploitation could lead to memory corruption and arbitrary code execution in the context of the browser.


119) Out-of-bounds read (CVE-ID: CVE-2026-4685)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Graphics: Canvas2D component when rendering canvas content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation may result in memory corruption and arbitrary code execution in the context of the browser.


120) Out-of-bounds read (CVE-ID: CVE-2026-4686)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Graphics: Canvas2D component when rendering canvas content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation may result in memory corruption and arbitrary code execution in the context of the browser.


121) Out-of-bounds write (CVE-ID: CVE-2026-4687)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions in the Telemetry component when handling telemetry data. A remote attacker can trick the victim into visiting a specially crafted website and escape the sandbox.

Successful exploitation could allow an attacker to execute code outside the browser's sandbox with elevated privileges.


122) Use After Free (CVE-ID: CVE-2026-4688)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox and execute arbitrary code.

The vulnerability exists due to use-after-free in the Disability Access APIs component when processing accessibility events. A remote attacker can trick the victim into visiting a specially crafted website to escape the sandbox and execute arbitrary code.


123) Integer overflow (CVE-ID: CVE-2026-4689)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions, integer overflow in the XPCOM component when processing data. A remote attacker can trick the victim into visiting a specially crafted website and escape the sandbox.

Exploitation could lead to sandbox escape and arbitrary code execution in the context of the underlying operating system.


124) Integer overflow (CVE-ID: CVE-2026-4690)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions, integer overflow in the XPCOM component when processing data. A remote attacker can trick the victim into visiting a specially crafted website and escape the sandbox.

Exploitation could lead to sandbox escape and arbitrary code execution in the context of the underlying operating system.


125) Use After Free (CVE-ID: CVE-2026-4691)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the CSS Parsing and Computation component when processing CSS content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation could result in memory corruption and arbitrary code execution in the context of the browser.


126) Improper Access Control (CVE-ID: CVE-2026-4692)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to sandbox escape in the Responsive Design Mode component when handling mode switching. A remote attacker can trick the victim into visiting a specially crafted website and escape the sandbox.

Successful exploitation could allow an attacker to execute code outside the browser's sandbox with elevated privileges.


127) Out-of-bounds read (CVE-ID: CVE-2026-4693)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Playback component when processing media content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation may result in memory corruption and arbitrary code execution in the context of the browser.


128) Integer overflow (CVE-ID: CVE-2026-4694)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions, integer overflow in the Graphics component when rendering graphical content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation could lead to memory corruption and arbitrary code execution in the context of the browser.


129) Out-of-bounds read (CVE-ID: CVE-2026-4695)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Web Codecs component when processing encoded media. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


130) Use After Free (CVE-ID: CVE-2026-4696)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Layout: Text and Fonts component when processing text content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation could result in memory corruption and arbitrary code execution in the context of the browser.


131) Out-of-bounds read (CVE-ID: CVE-2026-4697)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Web Codecs component when processing encoded media. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


132) Heap-based Buffer Overflow (CVE-ID: CVE-2026-4698)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing JavaScript code. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation could lead to memory corruption and arbitrary code execution in the context of the browser.


133) Out-of-bounds read (CVE-ID: CVE-2026-4699)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Layout: Text and Fonts component when processing text content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation may result in memory corruption and arbitrary code execution in the context of the browser.


134) Exposure of sensitive information to an unauthorized actor (CVE-ID: CVE-2026-4700)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass security mitigations.

The vulnerability exists due to improper input validation in the Networking: HTTP component when handling HTTP requests. A remote attacker can trick the victim into visiting a specially crafted website to bypass security mitigations.


135) Use After Free (CVE-ID: CVE-2026-4701)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the JavaScript Engine component when executing JavaScript code. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


136) Insufficient Control Flow Management (CVE-ID: CVE-2026-4702)

CWE-ID: CWE-691 - Insufficient Control Flow Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to JIT miscompilation in the JavaScript Engine component when executing JavaScript code. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


137) Resource exhaustion (CVE-ID: CVE-2026-4704)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to denial-of-service in the WebRTC: Signaling component when handling signaling messages. A remote attacker can trick the victim into visiting a specially crafted website to cause a denial of service.


138) Type conversion (CVE-ID: CVE-2026-4705)

CWE-ID: CWE-704 - Type conversion

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to undefined behavior in the WebRTC: Signaling component when processing signaling messages. A remote attacker can trick the victim into visiting a specially crafted website to cause a denial of service.


139) Out-of-bounds read (CVE-ID: CVE-2026-4706)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Graphics: Canvas2D component when rendering canvas content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation may result in memory corruption and arbitrary code execution in the context of the browser, though impact is somewhat limited.


140) Out-of-bounds read (CVE-ID: CVE-2026-4707)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Graphics: Canvas2D component when rendering canvas content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation may result in memory corruption and arbitrary code execution in the context of the browser, though impact is somewhat limited.


141) Out-of-bounds read (CVE-ID: CVE-2026-4708)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing graphical content. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


142) Out-of-bounds read (CVE-ID: CVE-2026-4709)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: GMP component when processing media content. A remote attacker can trick the victim into visiting a specially crafted website and to execute arbitrary code.

Exploitation may result in memory corruption and arbitrary code execution in the context of the browser, though impact is somewhat limited.


143) Out-of-bounds read (CVE-ID: CVE-2026-4710)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video component when processing media content. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


144) Use After Free (CVE-ID: CVE-2026-4711)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the Widget: Cocoa component when handling UI events. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


145) Exposure of sensitive information to an unauthorized actor (CVE-ID: CVE-2026-4712)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to information disclosure in the Widget: Cocoa component when handling UI events. A remote attacker can trick the victim into visiting a specially crafted website to disclose sensitive information.


146) Out-of-bounds read (CVE-ID: CVE-2026-4713)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing graphical content. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


147) Out-of-bounds read (CVE-ID: CVE-2026-4714)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video component when processing media content. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


148) Use of Uninitialized Variable (CVE-ID: CVE-2026-4715)

CWE-ID: CWE-457 - Use of Uninitialized Variable

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to uninitialized memory in the Graphics: Canvas2D component when processing graphical content. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


149) Out-of-bounds read (CVE-ID: CVE-2026-4716)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions and uninitialized memory in the JavaScript Engine component when executing JavaScript code. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


150) Improper Privilege Management (CVE-ID: CVE-2026-4717)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Netmonitor component when handling developer tools. A remote attacker can trick the victim into visiting a specially crafted website to escalate privileges.


151) Type conversion (CVE-ID: CVE-2026-4718)

CWE-ID: CWE-704 - Type conversion

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to undefined behavior in the WebRTC: Signaling component when processing signaling messages. A remote attacker can trick the victim into visiting a specially crafted website to cause a denial of service.


152) Out-of-bounds read (CVE-ID: CVE-2026-4719)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Graphics: Text component when rendering text. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


153) Out-of-bounds write (CVE-ID: CVE-2026-4720)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory safety bugs in multiple components when processing content. A remote attacker can trick the victim into visiting a specially crafted website to execute arbitrary code.


154) Out-of-bounds write (CVE-ID: CVE-2026-4721)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory safety bugs in multiple components when processing content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Multiple memory safety bugs were fixed; some showed evidence of memory corruption, indicating potential for arbitrary code execution.


155) Buffer overflow (CVE-ID: CVE-2026-5731)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


156) Integer overflow (CVE-ID: CVE-2026-5732)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the Graphics: Text component. A remote attacker can trick the victim into visiting a specially crafted website, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


157) Buffer overflow (CVE-ID: CVE-2026-5734)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


158) Use-after-free (CVE-ID: CVE-2026-6746)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Core & HTML component when rendering crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

User interaction is required to visit a crafted website or URL.


159) Use-after-free (CVE-ID: CVE-2026-6747)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the WebRTC component when handling crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


160) Use of uninitialized resource (CVE-ID: CVE-2026-6748)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to uninitialized memory in the Audio/Video: Web Codecs component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


161) Use of uninitialized resource (CVE-ID: CVE-2026-6749)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to uninitialized memory in the Graphics: Canvas2D component when rendering crafted web content. A remote attacker can cause the browser to process specially crafted content to disclose sensitive information.

User interaction is required to visit a crafted website or URL.


162) Improper access control (CVE-ID: CVE-2026-6750)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Graphics: WebRender component when rendering crafted web content. A remote attacker can cause the browser to process specially crafted content to escalate privileges.

User interaction is required to visit a crafted website or URL.


163) Use of uninitialized resource (CVE-ID: CVE-2026-6751)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to uninitialized memory in the Audio/Video: Web Codecs component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.


164) Out-of-bounds read (CVE-ID: CVE-2026-6752)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the WebRTC component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a crafted website or URL.


165) Buffer overflow (CVE-ID: CVE-2026-6753)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the WebRTC component when handling crafted web content. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


166) Use-after-free (CVE-ID: CVE-2026-6754)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the JavaScript Engine component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

User interaction is required to visit a crafted website or URL.


167) NULL pointer dereference (CVE-ID: CVE-2026-6757)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to invalid pointer usage in the JavaScript: WebAssembly component when processing crafted WebAssembly content. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


168) Use-after-free (CVE-ID: CVE-2026-6759)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the Widget: Cocoa component when handling local widget operations. A local user can trigger the vulnerable code path to cause a denial of service.


169) Improper access control (CVE-ID: CVE-2026-6761)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Networking component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to escalate privileges.

User interaction is required to visit a specially crafted website or URL.


170) Input validation error (CVE-ID: CVE-2026-6762)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to spoof the user interface.

The vulnerability exists due to improper input validation in the DOM: Core & HTML component when rendering crafted web content. A remote attacker can cause the browser to process specially crafted content to spoof the user interface.

User interaction is required to visit a crafted website or URL.


171) Protection Mechanism Failure (CVE-ID: CVE-2026-6763)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security restriction.

The vulnerability exists due to improper restriction enforcement in the File Handling component when processing crafted file handling operations. A remote attacker can trigger the vulnerable behavior to bypass a security restriction.


172) Buffer overflow (CVE-ID: CVE-2026-6764)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the DOM: Device Interfaces component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


173) Information disclosure (CVE-ID: CVE-2026-6765)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the Form Autofill component when handling autofill data in crafted web content. A remote attacker can cause the browser to expose autofill-related information to disclose sensitive information.

User interaction is required to visit a specially crafted website or URL.


174) Buffer overflow (CVE-ID: CVE-2026-6766)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the Libraries component in NSS when parsing crafted input. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


175) Input validation error (CVE-ID: CVE-2026-6767)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an unspecified flaw in the Libraries component in NSS when processing crafted input. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a crafted website or URL.


176) Improper access control (CVE-ID: CVE-2026-6769)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Debugger component when processing crafted web content. A remote attacker can trigger the vulnerable behavior to escalate privileges.

User interaction is required to visit a specially crafted website or URL.


177) Input validation error (CVE-ID: CVE-2026-6770)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input handling in the Storage: IndexedDB component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


178) Protection Mechanism Failure (CVE-ID: CVE-2026-6771)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security restriction.

The vulnerability exists due to improper restriction enforcement in the DOM: Security component when processing crafted web content. A remote attacker can trigger the vulnerable behavior to bypass a security restriction.

User interaction is required to visit a specially crafted website or URL.


179) Out-of-bounds read (CVE-ID: CVE-2026-6772)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the Libraries component in NSS when processing crafted input. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a crafted website or URL.


180) Buffer overflow (CVE-ID: CVE-2026-6776)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the WebRTC: Networking component when handling crafted web content. A remote attacker can cause the browser to process specially crafted content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


181) Buffer overflow (CVE-ID: CVE-2026-6785)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple components when rendering crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

The advisory states that some of the underlying bugs showed evidence of memory corruption.


182) Buffer overflow (CVE-ID: CVE-2026-6786)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple browser components when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

Some of the bugs showed evidence of memory corruption.


183) Out-of-bounds read (CVE-ID: CVE-2026-7320)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video component when processing media content. A remote attacker can cause the browser to process specially crafted media content to disclose sensitive information.


184) Input validation error (CVE-ID: CVE-2026-7321)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions in the WebRTC: Networking component when handling WebRTC network traffic. A remote attacker can trigger specially crafted WebRTC network interactions to escape the sandbox.

User interaction is required to visit a specially crafted website or URL.


185) Buffer overflow (CVE-ID: CVE-2026-7322)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption when processing crafted web content. A remote attacker can trigger memory safety bugs to execute arbitrary code.


186) Buffer overflow (CVE-ID: CVE-2026-7323)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption when rendering web content. A remote attacker can trigger memory corruption using specially crafted web content to execute arbitrary code.


187) Input validation error (CVE-ID: CVE-2026-8091)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in the Audio/Video: Playback component when processing media content. A remote attacker can supply specially crafted media content to execute arbitrary code.

User interaction is required to visit a specially crafted website or open a specially crafted URL.


188) Input validation error (CVE-ID: CVE-2026-8388)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in the JavaScript Engine: JIT component when processing crafted JavaScript. A remote attacker can supply specially crafted script content to execute arbitrary code.


189) Input validation error (CVE-ID: CVE-2026-8391)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an unspecified issue in the JavaScript Engine component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the system.


190) Protection mechanism failure (CVE-ID: CVE-2026-8401)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures in the Profile Backup component. An attacker can trick the victim into visiting a specially crafted website and bypass sandbox restrictions, leading to remote code execution. 


191) Out-of-bounds read (CVE-ID: CVE-2026-8946)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Web Codecs component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


192) Use-after-free (CVE-ID: CVE-2026-8947)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the DOM: Bindings (WebIDL) component when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


193) Improper access control (CVE-ID: CVE-2026-8950)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to bypass the same-origin policy.

The vulnerability exists due to improper access control in the Networking: HTTP component when handling crafted web content. A remote attacker can cause the browser to process crafted content to bypass the same-origin policy.

User interaction is required to visit a specially crafted website or URL.


194) Use-after-free (CVE-ID: CVE-2026-8953)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in the Disability Access APIs component when processing crafted web content. A remote attacker can trigger the flaw to escape the sandbox.

User interaction is required to visit a specially crafted website or URL.


195) Integer overflow (CVE-ID: CVE-2026-8954)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions and integer overflow in the Audio/Video component when processing crafted media content. A remote attacker can supply crafted media content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


196) Improper privilege management (CVE-ID: CVE-2026-8955)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Workers component when processing crafted web content. A remote attacker can trigger the flaw to escalate privileges.

User interaction is required to visit a specially crafted website or URL.


197) Integer overflow (CVE-ID: CVE-2026-8956)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Networking: JAR component when processing crafted web content. A remote attacker can supply crafted content to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


198) Improper privilege management (CVE-ID: CVE-2026-8957)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper access control in the Enterprise Policies component when modifying enterprise policy handling. A local user can manipulate enterprise policy behavior to escalate privileges.


199) Improper access control (CVE-ID: CVE-2026-8958)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to disclose sensitive information and escape the sandbox.

The vulnerability exists due to improper access control in the Security: Process Sandboxing component when processing crafted web content. A remote attacker can trigger the flaw to disclose sensitive information and escape the sandbox.

User interaction is required to visit a specially crafted website or URL.


200) Out-of-bounds read (CVE-ID: CVE-2026-8959)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local user to escape the sandbox.

The vulnerability exists due to incorrect boundary conditions in the Widget: Win32 component when handling local interaction with the application. A local user can trigger the flaw to escape the sandbox.

The issue affects the Win32-specific component.


201) Input validation error (CVE-ID: CVE-2026-8961)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to spoof content.

The vulnerability exists due to improper input validation in the Form Autofill component when rendering crafted web content. A remote attacker can present crafted content to spoof content.

User interaction is required to visit a specially crafted website or URL.


202) Protection Mechanism Failure (CVE-ID: CVE-2026-8962)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the DOM: Security component when processing crafted web content. A remote attacker can trigger the flaw to bypass a security mitigation.

User interaction is required to visit a specially crafted website or URL.


203) NULL pointer dereference (CVE-ID: CVE-2026-8968)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an invalid pointer dereference in the Audio/Video: Web Codecs component when processing crafted web content. A remote attacker can trigger the invalid pointer condition to cause a denial of service.

User interaction is required to visit a specially crafted website or URL.


204) Improper privilege management (CVE-ID: CVE-2026-8970)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Security component when processing crafted web content. A remote attacker can trigger the flaw to escalate privileges.

User interaction is required to visit a specially crafted website or URL.


205) Buffer overflow (CVE-ID: CVE-2026-8974)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger memory corruption to execute arbitrary code.

Some of the bugs showed evidence of memory corruption.


206) Buffer overflow (CVE-ID: CVE-2026-8975)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple components when processing crafted web content. A remote attacker can cause the browser to process specially crafted content to execute arbitrary code.

User interaction is required to visit a specially crafted website or URL.


Remediation

Install update from vendor's website.