Skip to main content
EPSS 0.2%top 90%

Security update for MozillaFirefox

0
Medium
Published: 08/19/2026 (08/19/2026, 13:10:07 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.14.0 ESR. - MFSA 2026-76 (bsc#1274867) * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics:Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Affected software

Affected versions
=140.14.0-1.el10_2.srcSUSEaarch64MozillaFirefox-140.14.0-160000.1.1.aarch64MozillaFirefox-branding-upstream-140.14.0-160000.1.1.aarch64MozillaFirefox-translations-common-140.14.0-160000.1.1.aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 14:46:13 UTC

Technical Analysis

This advisory covers a broad set of security vulnerabilities in Mozilla Thunderbird and Firefox components as packaged in Red Hat Enterprise Linux. The issues include use-after-free bugs (e.g., in Graphics: ImageLib, Canvas2D, JavaScript WebAssembly), privilege escalation flaws (e.g., in Graphics CanvasWebGL, Shell Integration, DOM Navigation), information disclosure vulnerabilities (e.g., in Graphics Text, DOM UI Events), site isolation issues (e.g., Graphics CanvasWebGL, Networking Cookies), and mitigation bypasses (e.g., Data Loss Prevention, Safe Browsing). These bugs were internally found and fixed in Firefox ESR 140.14, ESR 153.1, and Firefox 154. Red Hat has issued security updates for affected RHEL 9 and 10 AppStream and Extended Update Support versions, addressing these vulnerabilities. The vendor advisory confirms the availability of patches and provides detailed bug references and impact ratings.

Potential Impact

The vulnerabilities collectively pose a high security risk, including potential privilege escalation, information disclosure, and bypass of security mitigations. Exploitation could allow attackers to escalate privileges, access sensitive information, or bypass security boundaries within the affected Thunderbird and Firefox components. However, there are no known exploits in the wild at this time. The issues affect multiple critical components such as graphics rendering, networking, DOM handling, and JavaScript execution, increasing the potential attack surface.

Mitigation Recommendations

Red Hat has released official security updates addressing these vulnerabilities in Firefox ESR 140.14 and related versions for Red Hat Enterprise Linux 9 and 10. Users should apply the provided patches promptly following Red Hat's guidance at https://access.redhat.com/articles/11258. Since this is an official fix, applying the update fully mitigates the described vulnerabilities. No additional mitigation steps are required beyond applying the vendor-supplied patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:58899
Cve Count
31
Additional Cves
["CVE-2026-74935","CVE-2026-74936","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74948","CVE-2026-74949","CVE-2026-74953","CVE-2026-74957","CVE-2026-74959","CVE-2026-74960","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74967","CVE-2026-74969","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74983","CVE-2026-74987","CVE-2026-74990"]
State
PUBLISHED

Threat ID: 6a8c4c48acd9273b499be014

Added to database: 08/24/2026, 13:51:04 UTC

Last enriched: 09/09/2026, 14:46:13 UTC

Last updated: 10/08/2026, 06:48:19 UTC

Views: 54

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses