SB2026081838 - Multiple vulnerabilities in Mozilla Firefox and Firefox ESR
Published: August 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 58 vulnerabilities.
1) Observable discrepancy (CVE-ID: CVE-2026-74961)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a side-channel in the Web Audio component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
2) Buffer overflow (CVE-ID: CVE-2026-74946)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to escalate privileges.
3) Improper access control (CVE-ID: CVE-2026-74934)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to bypass site isolation.
4) Improper access control (CVE-ID: CVE-2026-74935)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Networking component when handling web content. A remote attacker can trigger crafted browser interactions to escalate privileges.
5) Use-after-free (CVE-ID: CVE-2026-74936)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
6) Use-after-free (CVE-ID: CVE-2026-74937)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript: GC component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to execute arbitrary code.
User interaction is required to visit a crafted website or URL.
7) Protection mechanism failure (CVE-ID: CVE-2026-74938)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to a protection mechanism failure in the JavaScript: GC component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass a security mitigation.
User interaction is required to visit a crafted website or URL.
8) Improper access control (CVE-ID: CVE-2026-74939)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted browser interactions to escalate privileges.
9) Use-after-free (CVE-ID: CVE-2026-74940)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Text component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
10) Improper privilege management (CVE-ID: CVE-2026-74941)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
11) Improper access control (CVE-ID: CVE-2026-74942)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Remote Settings Client component when processing remote settings data. A remote attacker can trigger crafted browser interactions to escalate privileges.
12) Use-after-free (CVE-ID: CVE-2026-74943)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: ImageLib component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
13) Use-after-free (CVE-ID: CVE-2026-74944)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
14) Information disclosure (CVE-ID: CVE-2026-74945)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics: Text component when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.
15) Access of Uninitialized Pointer (CVE-ID: CVE-2026-74947)
CWE-ID: CWE-824 - Access of Uninitialized Pointer
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an invalid pointer in the Graphics component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to escalate privileges.
User interaction is required to visit a crafted website or URL.
16) Origin validation error (CVE-ID: CVE-2026-74962)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper isolation enforcement in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to bypass site isolation.
User interaction is required to visit a specially crafted website or URL.
17) Information disclosure (CVE-ID: CVE-2026-74948)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics component when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.
18) Use-after-free (CVE-ID: CVE-2026-74949)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when rendering web content. A remote attacker can cause the browser to process specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
19) Improper access control (CVE-ID: CVE-2026-74950)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Downloads API component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to escalate privileges.
User interaction is required to visit a crafted website or URL.
20) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-74951)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking.
The vulnerability exists due to improper UI protection in Firefox for Android when rendering user interface elements. A remote attacker can present crafted content to perform clickjacking.
21) Improper access control (CVE-ID: CVE-2026-74952)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper access control in the Application Update component when performing update operations. A local user can trigger the vulnerable component to escalate privileges.
22) Improper privilege management (CVE-ID: CVE-2026-74953)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
23) Observable discrepancy (CVE-ID: CVE-2026-74954)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a side-channel in the Storage: Cache API component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
24) Improper access control (CVE-ID: CVE-2026-74955)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Request Handling component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to escalate privileges.
User interaction is required to visit a crafted website or URL.
25) Improper access control (CVE-ID: CVE-2026-74956)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the DOM: Service Workers component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass the same-origin policy.
User interaction is required to visit a crafted website or URL.
26) Protection mechanism failure (CVE-ID: CVE-2026-74957)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Safe Browsing component when processing web content. A remote attacker can cause the browser to handle specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
27) Information disclosure (CVE-ID: CVE-2026-74958)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the WebRTC component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
28) Protection mechanism failure (CVE-ID: CVE-2026-74959)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Storage: Cache API component when handling cached web content. A remote attacker can trigger specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
29) Origin validation error (CVE-ID: CVE-2026-74960)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper isolation enforcement in the WebExtensions component when handling extension-related web content. A remote attacker can cause the browser to process specially crafted web content to bypass site isolation.
User interaction is required to visit a specially crafted website or URL.
30) Origin validation error (CVE-ID: CVE-2026-74963)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to bypass the same-origin policy.
User interaction is required to visit a specially crafted website or URL.
31) Integer overflow (CVE-ID: CVE-2026-74977)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to cause a denial of service.
User interaction is required to visit a crafted website or URL.
32) Improper privilege management (CVE-ID: CVE-2026-74965)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Shell Integration component when processing crafted content. A remote attacker can trigger specially crafted content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
33) Information disclosure (CVE-ID: CVE-2026-74966)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Form Autofill component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
34) Origin validation error (CVE-ID: CVE-2026-74967)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Audio/Video: Playback component when processing media content. A remote attacker can cause the browser to handle specially crafted media content to bypass the same-origin policy.
User interaction is required to visit a specially crafted website or URL.
35) Protection mechanism failure (CVE-ID: CVE-2026-74968)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Graphics: WebRender component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass site isolation.
User interaction is required to visit a crafted website or URL.
36) Use-after-free (CVE-ID: CVE-2026-74969)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Layout: Text and Fonts component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
37) Protection mechanism failure (CVE-ID: CVE-2026-74970)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Graphics component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass site isolation.
User interaction is required to visit a crafted website or URL.
38) Information disclosure (CVE-ID: CVE-2026-74971)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the DOM: UI Events & Focus Handling component when processing web content. A remote attacker can trigger specially crafted web content to disclose sensitive information.
39) Information disclosure (CVE-ID: CVE-2026-74972)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the DOM: Push Subscriptions component when handling push subscription data. A remote attacker can trigger specially crafted web content to disclose sensitive information.
User interaction is required to visit a specially crafted website or URL.
40) Use-after-free (CVE-ID: CVE-2026-74973)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a race condition leading to use-after-free in the Graphics component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
41) Improper access control (CVE-ID: CVE-2026-74974)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Graphics: ImageLib component when rendering content. A remote attacker can cause the browser to process crafted content to bypass the same-origin policy.
42) Spoofing attack (CVE-ID: CVE-2026-74975)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to improper UI representation in the Downloads component when displaying download information. A remote attacker can present crafted content to spoof the user interface.
43) Incorrect calculation (CVE-ID: CVE-2026-74976)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing crafted script content. A remote attacker can cause the browser to execute specially crafted script content to cause a denial of service.
User interaction is required to visit a specially crafted website or URL.
44) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-74978)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking.
The vulnerability exists due to improper UI protection in the Widget component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to perform clickjacking.
User interaction is required to visit a crafted website or URL.
45) Integer overflow (CVE-ID: CVE-2026-74964)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics component when rendering crafted web content. A remote attacker can cause the browser to process specially crafted web content to cause a denial of service.
User interaction is required to visit a specially crafted website or URL.
46) Protection mechanism failure (CVE-ID: CVE-2026-74979)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to a protection mechanism failure in the Add-ons Manager component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass a security mitigation.
User interaction is required to visit a crafted website or URL.
47) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-74980)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking.
The vulnerability exists due to improper UI protection in the Downloads component when displaying download information. A remote attacker can present crafted content to perform clickjacking.
48) Protection mechanism failure (CVE-ID: CVE-2026-74981)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Audio/Video: Web Codecs component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass site isolation.
User interaction is required to visit a crafted website or URL.
49) Input validation error (CVE-ID: CVE-2026-74982)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the Widget component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to cause a denial of service.
User interaction is required to visit a crafted website or URL.
50) Protection mechanism failure (CVE-ID: CVE-2026-74983)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Data Loss Prevention component when processing web content. A remote attacker can trigger specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
51) Race condition (CVE-ID: CVE-2026-74984)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in the JavaScript Engine component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to cause a denial of service.
User interaction is required to visit a crafted website or URL.
52) Improper access control (CVE-ID: CVE-2026-74985)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Enterprise Policies component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to escalate privileges.
User interaction is required to visit a crafted website or URL.
53) Protection mechanism failure (CVE-ID: CVE-2026-74986)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the CSS Parsing and Computation component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass site isolation.
User interaction is required to visit a crafted website or URL.
54) Buffer overflow (CVE-ID: CVE-2026-74987)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
The advisory states that some of the internally found bugs showed evidence of memory corruption or another security-relevant defect.
55) Buffer overflow (CVE-ID: CVE-2026-74988)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to execute arbitrary code.
The advisory states that some internally found bugs showed evidence of memory corruption or another security-relevant defect.
56) Buffer overflow (CVE-ID: CVE-2026-74989)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to memory corruption in multiple unspecified components when processing web content. A remote attacker can supply crafted web content to cause a denial of service.
Some of the internally found bugs showed evidence of memory corruption or another security-relevant defect.
57) Buffer overflow (CVE-ID: CVE-2026-74990)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when rendering content or handling browser operations. A remote attacker can trigger crafted browser interactions to execute arbitrary code.
Multiple internally found bugs are covered by this entry, and the advisory notes that some showed evidence of memory corruption or another security-relevant defect.
58) Improper access control (CVE-ID: CVE-2026-75874)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper isolation in the Remote Settings Client component when handling remote settings data. A remote attacker can trigger the vulnerable component to escape the sandbox.
Remediation
Install update from vendor's website.
References
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050380
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-75/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059997
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050584
- https://bugzilla.mozilla.org/show_bug.cgi?id=2051013
- https://bugzilla.mozilla.org/show_bug.cgi?id=2052688
- https://bugzilla.mozilla.org/show_bug.cgi?id=2053337
- https://bugzilla.mozilla.org/show_bug.cgi?id=2053688
- https://bugzilla.mozilla.org/show_bug.cgi?id=2054416
- https://bugzilla.mozilla.org/show_bug.cgi?id=2054842
- https://bugzilla.mozilla.org/show_bug.cgi?id=2055056
- https://bugzilla.mozilla.org/show_bug.cgi?id=2056571
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057308
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057778
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057808
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060010
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050425
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060106
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060245
- https://bugzilla.mozilla.org/show_bug.cgi?id=1880253
- https://bugzilla.mozilla.org/show_bug.cgi?id=1978587
- https://bugzilla.mozilla.org/show_bug.cgi?id=2021757
- https://bugzilla.mozilla.org/show_bug.cgi?id=2022382
- https://bugzilla.mozilla.org/show_bug.cgi?id=2025732
- https://bugzilla.mozilla.org/show_bug.cgi?id=2029265
- https://bugzilla.mozilla.org/show_bug.cgi?id=2032406
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041906
- https://bugzilla.mozilla.org/show_bug.cgi?id=2045368
- https://bugzilla.mozilla.org/show_bug.cgi?id=2047853
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049148
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050482
- https://bugzilla.mozilla.org/show_bug.cgi?id=2028440
- https://bugzilla.mozilla.org/show_bug.cgi?id=2053455
- https://bugzilla.mozilla.org/show_bug.cgi?id=2054776
- https://bugzilla.mozilla.org/show_bug.cgi?id=2055697
- https://bugzilla.mozilla.org/show_bug.cgi?id=2055738
- https://bugzilla.mozilla.org/show_bug.cgi?id=2056065
- https://bugzilla.mozilla.org/show_bug.cgi?id=2056558
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057204
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059053
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060357
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061794
- https://bugzilla.mozilla.org/show_bug.cgi?id=1842361
- https://bugzilla.mozilla.org/show_bug.cgi?id=1952164
- https://bugzilla.mozilla.org/show_bug.cgi?id=2036097
- https://bugzilla.mozilla.org/show_bug.cgi?id=2053327
- https://bugzilla.mozilla.org/show_bug.cgi?id=2045676
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049034
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050480
- https://bugzilla.mozilla.org/show_bug.cgi?id=2051788
- https://bugzilla.mozilla.org/show_bug.cgi?id=2051897
- https://bugzilla.mozilla.org/show_bug.cgi?id=2053670
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059825
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060048
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048797
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2050536
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053272
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053579
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057115
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057116
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057130
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057991
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057995
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058002
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058008
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058032
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058102
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058667
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1500946
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1788109
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045379
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045380
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2049339
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2049393
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053580
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054662
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054665
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054673
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054785
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058645
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059424
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045796
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2046734
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2051424
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054721
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057994
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058094
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058611
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058615
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058616
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2061315
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2018164
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045404
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045507
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045711
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2052403
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053174
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054643
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054667
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054671
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054674
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054687
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054717
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054761
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054787
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2055676
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2056779
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2056781
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058629
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2059019
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2059138
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053153
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053262
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054763
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2059198
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2059224
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2027388%2C2029750%2C2029794%2C2043298%2C2045126%2C2049810%2C2051741
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045774
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048490
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2050864
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053159
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053260
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053261
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053582
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053599
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053607
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053608
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2053853
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054626
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054627
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054635
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054677
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054740
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054832
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2056792
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057098
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057100
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057101
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057103
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057117
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2057118
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058048
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058049
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058622
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058623
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058665
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058666
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2059121
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2059164
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2059188
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045762
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2052401
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2058208
- https://bugzilla.mozilla.org/show_bug.cgi?id=2039972