SB20260921203 - SUSE update for MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen
Published: September 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 139 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-16349)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation. A remote attacker can convince the victim to visit a specially crafted website or URL to bypass the same-origin policy.
2) Input validation error (CVE-ID: CVE-2026-16350)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: cubeb component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
3) Use-after-free (CVE-ID: CVE-2026-16351)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Navigation component when handling navigation. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
4) Use-after-free (CVE-ID: CVE-2026-16352)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Disability Access APIs component when interacting with accessibility functionality. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
5) NULL pointer dereference (CVE-ID: CVE-2026-16353)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to an invalid pointer in the DOM: Bindings (WebIDL) component when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
6) Information disclosure (CVE-ID: CVE-2026-16354)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics: ImageLib component when processing image content. A remote attacker can convince the victim to visit a specially crafted website or URL to disclose sensitive information.
7) Incorrect calculation (CVE-ID: CVE-2026-16355)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing script content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
8) Use-after-free (CVE-ID: CVE-2026-16356)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Disability Access APIs component when interacting with accessibility functionality. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
9) Input validation error (CVE-ID: CVE-2026-16357)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing rendered content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
10) Improper access control (CVE-ID: CVE-2026-16358)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Graphics: WebRender component when rendering content. A remote attacker can convince the victim to visit a specially crafted website or URL to bypass site isolation.
11) Input validation error (CVE-ID: CVE-2026-16359)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: GMP component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
12) Buffer overflow (CVE-ID: CVE-2026-16360)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
Some of the underlying bugs showed evidence of memory corruption.
13) Use-after-free (CVE-ID: CVE-2026-16362)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the WebRTC: Audio/Video component when processing real-time audio or video content. A remote attacker can trigger the flaw using crafted real-time media interactions to execute arbitrary code.
14) Incorrect calculation (CVE-ID: CVE-2026-16363)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to JIT miscompilation in the JavaScript: WebAssembly component when compiling and executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to execute arbitrary code.
15) Buffer overflow (CVE-ID: CVE-2026-16364)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Playback component when processing audio or video content. A remote attacker can supply crafted media content to execute arbitrary code.
16) Improper privilege management (CVE-ID: CVE-2026-16365)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Workers component when handling worker operations. A remote attacker can trigger crafted worker behavior to escalate privileges.
17) Improper privilege management (CVE-ID: CVE-2026-16366)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to escalate privileges.
18) NULL pointer dereference (CVE-ID: CVE-2026-16367)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to invalid pointer dereference in the Disability Access APIs component when interacting with accessibility features. A remote attacker can trigger crafted interaction with accessibility features to escape the sandbox.
19) Out-of-bounds read (CVE-ID: CVE-2026-16368)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect boundary conditions in the JavaScript: WebAssembly component when compiling or executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to cause a denial of service.
20) Integer overflow (CVE-ID: CVE-2026-16369)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow in the JavaScript: WebAssembly component when compiling or executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to execute arbitrary code.
21) Protection mechanism failure (CVE-ID: CVE-2026-16370)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.
22) Improper privilege management (CVE-ID: CVE-2026-16371)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to escalate privileges.
23) Improper privilege management (CVE-ID: CVE-2026-16372)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Content Processes component when handling content processes. A remote attacker can trigger crafted content process behavior to escalate privileges.
24) Information disclosure (CVE-ID: CVE-2026-16373)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to information exposure in the Privacy component when handling privacy-related functionality. A remote attacker can trigger crafted interactions to disclose sensitive information.
This issue is specific to Firefox for Android.
25) Information disclosure (CVE-ID: CVE-2026-16374)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Framework component in DevTools when using developer tools functionality. A remote attacker can trigger the flaw through crafted developer tools interactions to disclose sensitive information.
26) Protection mechanism failure (CVE-ID: CVE-2026-16375)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Networking: HTTP component when handling HTTP traffic. A remote attacker can trigger crafted HTTP behavior to bypass site isolation.
27) Input validation error (CVE-ID: CVE-2026-16376)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input handling in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to cause a denial of service.
28) Protection mechanism failure (CVE-ID: CVE-2026-16377)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the PDF Viewer component when rendering PDF content. A remote attacker can supply crafted PDF content to bypass a security restriction.
29) Input validation error (CVE-ID: CVE-2026-16378)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to improper input handling in the DOM: Copy & Paste and Drag & Drop component when handling copy, paste, and drag-and-drop operations. A remote attacker can trigger crafted user interface interactions to perform unauthorized actions.
30) Improper privilege management (CVE-ID: CVE-2026-16379)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Content Processes component when handling content processes. A remote attacker can trigger crafted content process behavior to escalate privileges.
31) Protection mechanism failure (CVE-ID: CVE-2026-16380)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.
32) Improper access control (CVE-ID: CVE-2026-16381)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Networking: DNS component when resolving DNS requests. A remote attacker can trigger crafted DNS behavior to bypass the same-origin policy.
33) Protection mechanism failure (CVE-ID: CVE-2026-16382)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the DOM: Service Workers component when handling service worker operations. A remote attacker can trigger crafted service worker behavior to bypass a security mitigation.
34) Protection mechanism failure (CVE-ID: CVE-2026-16383)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security restriction.
35) Use of uninitialized resource (CVE-ID: CVE-2026-16384)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.
36) Use of uninitialized resource (CVE-ID: CVE-2026-16385)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.
37) Use of uninitialized resource (CVE-ID: CVE-2026-16386)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.
38) Protection mechanism failure (CVE-ID: CVE-2026-16387)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass site isolation.
39) Improper access control (CVE-ID: CVE-2026-16388)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper access control in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to escape the sandbox.
40) Integer overflow (CVE-ID: CVE-2026-16389)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Libraries component in NSS when processing input. A remote attacker can supply crafted input to cause a denial of service.
The advisory also reports incorrect boundary conditions in the same component.
41) Protection mechanism failure (CVE-ID: CVE-2026-16390)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the Enterprise Policies component when applying enterprise policies. A remote attacker can trigger crafted policy conditions to bypass a security restriction.
42) Information disclosure (CVE-ID: CVE-2026-16391)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Storage: IndexedDB component when handling stored web data. A remote attacker can trigger crafted storage interactions to disclose sensitive information.
43) Incorrect calculation (CVE-ID: CVE-2026-16392)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when compiling script code. A remote attacker can supply crafted script code to execute arbitrary code.
44) Buffer overflow (CVE-ID: CVE-2026-16393)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect boundary conditions in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to cause a denial of service.
45) Protection mechanism failure (CVE-ID: CVE-2026-16394)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the DOM: Security component when handling security checks. A remote attacker can trigger crafted behavior to bypass a security mitigation.
46) Integer overflow (CVE-ID: CVE-2026-16395)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Audio/Video component when processing audio or video content. A remote attacker can supply crafted media content to cause a denial of service.
47) Improper privilege management (CVE-ID: CVE-2026-16396)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in WebExtensions when using extension functionality. A remote user can abuse extension functionality to escalate privileges.
Exploitation requires the use of WebExtensions.
48) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-16397)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking attacks.
The vulnerability exists due to improper user interface control in the WebExtensions component when rendering extension user interface elements. A remote attacker can present crafted interface elements to perform clickjacking attacks.
This issue is specific to Firefox for Android.
49) Improper access control (CVE-ID: CVE-2026-16398)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper access control in the Graphics component when rendering content. A remote attacker can supply crafted content to bypass site isolation restrictions.
50) Improper access control (CVE-ID: CVE-2026-16399)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to bypass site isolation restrictions.
51) Information disclosure (CVE-ID: CVE-2026-16400)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to information exposure in the DOM: Security component when handling security checks. A remote attacker can trigger crafted behavior to disclose sensitive information.
52) Improper privilege management (CVE-ID: CVE-2026-16401)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Data Loss Prevention component when handling data loss prevention functionality. A remote attacker can trigger crafted behavior to escalate privileges.
53) Integer overflow (CVE-ID: CVE-2026-16402)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics: ImageLib component when processing image content. A remote attacker can supply crafted image content to cause a denial of service.
54) Spoofing attack (CVE-ID: CVE-2026-16403)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof trusted content.
The vulnerability exists due to improper user interface control in the Address Bar component when displaying address information. A remote attacker can present crafted address information to spoof trusted content.
55) Spoofing attack (CVE-ID: CVE-2026-16404)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof trusted content.
The vulnerability exists due to improper user interface control in Firefox for Android when displaying content. A remote attacker can present crafted content to spoof trusted content.
This issue is specific to Firefox for Android.
56) Information disclosure (CVE-ID: CVE-2026-16405)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Networking: WebSockets component when handling WebSocket connections. A remote attacker can trigger crafted WebSocket behavior to disclose sensitive information.
57) Protection mechanism failure (CVE-ID: CVE-2026-16406)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.
58) Protection mechanism failure (CVE-ID: CVE-2026-16407)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the DOM: Service Workers component when handling service worker operations. A remote attacker can trigger crafted service worker behavior to bypass a security mitigation.
59) Integer overflow (CVE-ID: CVE-2026-16408)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Audio/Video: Playback component when processing audio or video content. A remote attacker can supply crafted media content to cause a denial of service.
60) NULL pointer dereference (CVE-ID: CVE-2026-16409)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to invalid pointer dereference in the Security: PSM component when handling security operations. A remote attacker can trigger crafted behavior to cause a denial of service.
61) Incorrect calculation (CVE-ID: CVE-2026-16410)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when compiling script code. A remote attacker can supply crafted script code to cause a denial of service.
62) Buffer overflow (CVE-ID: CVE-2026-16411)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in Firefox for Android when processing content. A remote attacker can trigger memory safety bugs to execute arbitrary code.
The advisory states that some of these bugs showed evidence of memory corruption.
63) Buffer overflow (CVE-ID: CVE-2026-16412)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing crafted content. A remote attacker can trigger memory corruption using crafted content to execute arbitrary code.
Mozilla reported that some of the underlying bugs showed evidence of memory corruption.
64) Improper access control (CVE-ID: CVE-2026-74934)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to bypass site isolation.
65) Improper access control (CVE-ID: CVE-2026-74935)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Networking component when handling web content. A remote attacker can trigger crafted browser interactions to escalate privileges.
66) Use-after-free (CVE-ID: CVE-2026-74936)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
67) Use-after-free (CVE-ID: CVE-2026-74937)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript: GC component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to execute arbitrary code.
User interaction is required to visit a crafted website or URL.
68) Protection mechanism failure (CVE-ID: CVE-2026-74938)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to a protection mechanism failure in the JavaScript: GC component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass a security mitigation.
User interaction is required to visit a crafted website or URL.
69) Improper access control (CVE-ID: CVE-2026-74939)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted browser interactions to escalate privileges.
70) Use-after-free (CVE-ID: CVE-2026-74940)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Text component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
71) Improper privilege management (CVE-ID: CVE-2026-74941)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
72) Improper access control (CVE-ID: CVE-2026-74942)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Remote Settings Client component when processing remote settings data. A remote attacker can trigger crafted browser interactions to escalate privileges.
73) Use-after-free (CVE-ID: CVE-2026-74943)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: ImageLib component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
74) Use-after-free (CVE-ID: CVE-2026-74944)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
75) Information disclosure (CVE-ID: CVE-2026-74945)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics: Text component when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.
76) Buffer overflow (CVE-ID: CVE-2026-74946)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics: CanvasWebGL component when rendering web content. A remote attacker can cause the browser to process crafted content to escalate privileges.
77) Access of Uninitialized Pointer (CVE-ID: CVE-2026-74947)
CWE-ID: CWE-824 - Access of Uninitialized Pointer
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an invalid pointer in the Graphics component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to escalate privileges.
User interaction is required to visit a crafted website or URL.
78) Information disclosure (CVE-ID: CVE-2026-74948)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics component when rendering content. A remote attacker can cause the browser to process crafted content to disclose sensitive information.
79) Use-after-free (CVE-ID: CVE-2026-74949)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when rendering web content. A remote attacker can cause the browser to process specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
80) Improper access control (CVE-ID: CVE-2026-74950)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Downloads API component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to escalate privileges.
User interaction is required to visit a crafted website or URL.
81) Improper access control (CVE-ID: CVE-2026-74952)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper access control in the Application Update component when performing update operations. A local user can trigger the vulnerable component to escalate privileges.
82) Improper privilege management (CVE-ID: CVE-2026-74953)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
83) Observable discrepancy (CVE-ID: CVE-2026-74954)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a side-channel in the Storage: Cache API component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
84) Improper access control (CVE-ID: CVE-2026-74955)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Request Handling component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to escalate privileges.
User interaction is required to visit a crafted website or URL.
85) Improper access control (CVE-ID: CVE-2026-74956)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the DOM: Service Workers component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass the same-origin policy.
User interaction is required to visit a crafted website or URL.
86) Protection mechanism failure (CVE-ID: CVE-2026-74957)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Safe Browsing component when processing web content. A remote attacker can cause the browser to handle specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
87) Information disclosure (CVE-ID: CVE-2026-74958)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the WebRTC component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
88) Protection mechanism failure (CVE-ID: CVE-2026-74959)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Storage: Cache API component when handling cached web content. A remote attacker can trigger specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
89) Origin validation error (CVE-ID: CVE-2026-74960)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper isolation enforcement in the WebExtensions component when handling extension-related web content. A remote attacker can cause the browser to process specially crafted web content to bypass site isolation.
User interaction is required to visit a specially crafted website or URL.
90) Observable discrepancy (CVE-ID: CVE-2026-74961)
CWE-ID: CWE-203 - Observable discrepancy
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to a side-channel in the Web Audio component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
91) Origin validation error (CVE-ID: CVE-2026-74962)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper isolation enforcement in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to bypass site isolation.
User interaction is required to visit a specially crafted website or URL.
92) Origin validation error (CVE-ID: CVE-2026-74963)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Networking: Cookies component when handling cookie-related web content. A remote attacker can trigger specially crafted web content to bypass the same-origin policy.
User interaction is required to visit a specially crafted website or URL.
93) Integer overflow (CVE-ID: CVE-2026-74964)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics component when rendering crafted web content. A remote attacker can cause the browser to process specially crafted web content to cause a denial of service.
User interaction is required to visit a specially crafted website or URL.
94) Improper privilege management (CVE-ID: CVE-2026-74965)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Shell Integration component when processing crafted content. A remote attacker can trigger specially crafted content to escalate privileges.
User interaction is required to visit a specially crafted website or URL.
95) Information disclosure (CVE-ID: CVE-2026-74966)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Form Autofill component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
96) Origin validation error (CVE-ID: CVE-2026-74967)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Audio/Video: Playback component when processing media content. A remote attacker can cause the browser to handle specially crafted media content to bypass the same-origin policy.
User interaction is required to visit a specially crafted website or URL.
97) Protection mechanism failure (CVE-ID: CVE-2026-74968)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Graphics: WebRender component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass site isolation.
User interaction is required to visit a crafted website or URL.
98) Use-after-free (CVE-ID: CVE-2026-74969)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Layout: Text and Fonts component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
99) Protection mechanism failure (CVE-ID: CVE-2026-74970)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Graphics component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass site isolation.
User interaction is required to visit a crafted website or URL.
100) Information disclosure (CVE-ID: CVE-2026-74971)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the DOM: UI Events & Focus Handling component when processing web content. A remote attacker can trigger specially crafted web content to disclose sensitive information.
101) Information disclosure (CVE-ID: CVE-2026-74972)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the DOM: Push Subscriptions component when handling push subscription data. A remote attacker can trigger specially crafted web content to disclose sensitive information.
User interaction is required to visit a specially crafted website or URL.
102) Use-after-free (CVE-ID: CVE-2026-74973)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a race condition leading to use-after-free in the Graphics component when rendering content. A remote attacker can cause the browser to process crafted content to execute arbitrary code.
103) Improper access control (CVE-ID: CVE-2026-74974)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Graphics: ImageLib component when rendering content. A remote attacker can cause the browser to process crafted content to bypass the same-origin policy.
104) Incorrect calculation (CVE-ID: CVE-2026-74976)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing crafted script content. A remote attacker can cause the browser to execute specially crafted script content to cause a denial of service.
User interaction is required to visit a specially crafted website or URL.
105) Integer overflow (CVE-ID: CVE-2026-74977)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to cause a denial of service.
User interaction is required to visit a crafted website or URL.
106) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-74978)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking.
The vulnerability exists due to improper UI protection in the Widget component when rendering crafted web content. A remote attacker can cause the victim to visit a specially crafted website to perform clickjacking.
User interaction is required to visit a crafted website or URL.
107) Protection mechanism failure (CVE-ID: CVE-2026-74979)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to a protection mechanism failure in the Add-ons Manager component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass a security mitigation.
User interaction is required to visit a crafted website or URL.
108) Protection mechanism failure (CVE-ID: CVE-2026-74981)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Audio/Video: Web Codecs component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass site isolation.
User interaction is required to visit a crafted website or URL.
109) Input validation error (CVE-ID: CVE-2026-74982)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the Widget component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to cause a denial of service.
User interaction is required to visit a crafted website or URL.
110) Protection mechanism failure (CVE-ID: CVE-2026-74983)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper protection mechanism implementation in the Data Loss Prevention component when processing web content. A remote attacker can trigger specially crafted web content to bypass a security mitigation.
User interaction is required to visit a specially crafted website or URL.
111) Race condition (CVE-ID: CVE-2026-74984)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in the JavaScript Engine component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to cause a denial of service.
User interaction is required to visit a crafted website or URL.
112) Improper access control (CVE-ID: CVE-2026-74985)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Enterprise Policies component when handling crafted web content. A remote attacker can cause the victim to visit a specially crafted website to escalate privileges.
User interaction is required to visit a crafted website or URL.
113) Protection mechanism failure (CVE-ID: CVE-2026-74986)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the CSS Parsing and Computation component when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to bypass site isolation.
User interaction is required to visit a crafted website or URL.
114) Buffer overflow (CVE-ID: CVE-2026-74987)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can cause the browser to handle specially crafted web content to execute arbitrary code.
The advisory states that some of the internally found bugs showed evidence of memory corruption or another security-relevant defect.
115) Buffer overflow (CVE-ID: CVE-2026-74988)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing crafted web content. A remote attacker can cause the victim to visit a specially crafted website to execute arbitrary code.
The advisory states that some internally found bugs showed evidence of memory corruption or another security-relevant defect.
116) Buffer overflow (CVE-ID: CVE-2026-74990)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when rendering content or handling browser operations. A remote attacker can trigger crafted browser interactions to execute arbitrary code.
Multiple internally found bugs are covered by this entry, and the advisory notes that some showed evidence of memory corruption or another security-relevant defect.
117) Improper access control (CVE-ID: CVE-2026-75874)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper isolation in the Remote Settings Client component when handling remote settings data. A remote attacker can trigger the vulnerable component to escape the sandbox.
118) Use-after-free (CVE-ID: CVE-2026-84118)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the JavaScript: GC component when processing crafted web content. A remote attacker can trigger garbage collection with crafted content to execute arbitrary code.
User interaction is required to visit a crafted website or URL.
119) Use-after-free (CVE-ID: CVE-2026-84119)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in DOM: Navigation component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.
User interaction is required.
120) Use-after-free (CVE-ID: CVE-2026-84120)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in Audio/Video component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to execute arbitrary code.
User interaction is required.
121) Use-after-free (CVE-ID: CVE-2026-84121)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in DOM: Security component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escape the sandbox.
User interaction is required.
122) Use-after-free (CVE-ID: CVE-2026-84122)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Audio/Video component when processing crafted media content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
123) Use-after-free (CVE-ID: CVE-2026-84123)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use-after-free in the Graphics: WebGPU component when processing crafted web content. A remote attacker can trigger the vulnerable condition to escalate privileges.
User interaction is required to visit a crafted website or URL.
124) Use-after-free (CVE-ID: CVE-2026-84124)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can trigger a use-after-free condition to execute arbitrary code.
User interaction is required to visit a specially crafted website or URL.
125) Use-after-free (CVE-ID: CVE-2026-84125)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing crafted web content. A remote attacker can trigger the vulnerable condition to execute arbitrary code.
User interaction is required to visit a crafted website or URL.
126) Protection mechanism failure (CVE-ID: CVE-2026-84129)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper isolation in the DOM: Navigation component when handling crafted web navigation. A remote attacker can trigger crafted navigation to bypass site isolation restrictions.
User interaction is required to visit a crafted website or URL.
127) Information disclosure (CVE-ID: CVE-2026-84130)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics: WebGPU component when processing crafted web content. A remote attacker can trigger the vulnerable behavior to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
128) NULL pointer dereference (CVE-ID: CVE-2026-84131)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to invalid pointer dereference in Graphics component when processing web content. A remote attacker can convince the victim to visit a specially crafted website to escalate privileges.
User interaction is required.
129) Information disclosure (CVE-ID: CVE-2026-84132)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper information exposure in the Networking: HTTP component when handling crafted web requests. A remote attacker can trigger the vulnerable behavior to disclose sensitive information.
User interaction is required to visit a crafted website or URL.
130) Protection mechanism failure (CVE-ID: CVE-2026-84133)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper isolation in the DOM: Push Subscriptions component when handling crafted web content. A remote attacker can trigger the vulnerable behavior to bypass site isolation restrictions.
User interaction is required to visit a crafted website or URL.
131) Input validation error (CVE-ID: CVE-2026-84134)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error in the profile backup component. A remote attacker can bypass implemented security restrictions.
132) Input validation error (CVE-ID: CVE-2026-84136)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an unspecified error in the DOM navigation component. A remote attacker can bypass implemented security restrictions.
133) Origin validation error (CVE-ID: CVE-2026-84137)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof content.
The vulnerability exists due to improper origin validation in the DOM: Core & HTML component when rendering crafted web content. A remote attacker can present crafted content to spoof content.
User interaction is required to visit a crafted website or URL.
134) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-84139)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking attacks.
The vulnerability exists due to improper UI protection in the DOM: Events component when rendering crafted web content. A remote attacker can present crafted content to perform clickjacking attacks.
User interaction is required to interact with crafted content.
135) Protection mechanism failure (CVE-ID: CVE-2026-84140)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper isolation in the DOM: Navigation component when handling crafted web navigation. A remote attacker can trigger crafted navigation to bypass site isolation restrictions.
User interaction is required to visit a crafted website or URL.
136) Integer overflow (CVE-ID: CVE-2026-84141)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics: ImageLib component when parsing crafted image content. A remote attacker can supply crafted image content to cause a denial of service.
User interaction is required to visit a crafted website or URL.
137) Buffer overflow (CVE-ID: CVE-2026-84143)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger a security-relevant defect to execute arbitrary code.
The advisory describes multiple internally found bugs, some of which showed evidence of memory corruption or another security-relevant defect.
138) Buffer overflow (CVE-ID: CVE-2026-84144)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple unspecified components when processing crafted web content. A remote attacker can trigger the vulnerable behavior to execute arbitrary code.
The advisory states that some internally found bugs showed evidence of memory corruption or another security-relevant defect.
139) Buffer overflow (CVE-ID: CVE-2026-84145)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to memory corruption or another security-relevant defect in multiple unspecified components when processing web content. A remote attacker can convince the victim to visit a specially crafted website to cause a denial of service or execute arbitrary code.
The issue covers multiple internally found bugs.
Remediation
Install update from vendor's website.