Skip to main content

Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen

0
Critical
Published: 08/31/2026 (08/31/2026, 15:42:15 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.1.0 ESR. * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
openSUSE-SU-2026:21713-1
Cve Count
115
Additional Cves
["CVE-2026-16350","CVE-2026-16351","CVE-2026-16352","CVE-2026-16353","CVE-2026-16354","CVE-2026-16355","CVE-2026-16356","CVE-2026-16357","CVE-2026-16358","CVE-2026-16359","CVE-2026-16360","CVE-2026-16362","CVE-2026-16363","CVE-2026-16364","CVE-2026-16365","CVE-2026-16366","CVE-2026-16367","CVE-2026-16368","CVE-2026-16369","CVE-2026-16370","CVE-2026-16371","CVE-2026-16372","CVE-2026-16373","CVE-2026-16374","CVE-2026-16375","CVE-2026-16376","CVE-2026-16377","CVE-2026-16378","CVE-2026-16379","CVE-2026-16380","CVE-2026-16381","CVE-2026-16382","CVE-2026-16383","CVE-2026-16384","CVE-2026-16385","CVE-2026-16386","CVE-2026-16387","CVE-2026-16388","CVE-2026-16389","CVE-2026-16390","CVE-2026-16391","CVE-2026-16392","CVE-2026-16393","CVE-2026-16394","CVE-2026-16395","CVE-2026-16396","CVE-2026-16397","CVE-2026-16398","CVE-2026-16399","CVE-2026-16400","CVE-2026-16401","CVE-2026-16402","CVE-2026-16403","CVE-2026-16404","CVE-2026-16405","CVE-2026-16406","CVE-2026-16407","CVE-2026-16408","CVE-2026-16409","CVE-2026-16410","CVE-2026-16411","CVE-2026-16412","CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74937","CVE-2026-74938","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74947","CVE-2026-74948","CVE-2026-74949","CVE-2026-74950","CVE-2026-74953","CVE-2026-74954","CVE-2026-74955","CVE-2026-74956","CVE-2026-74957","CVE-2026-74958","CVE-2026-74959","CVE-2026-74960","CVE-2026-74961","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74966","CVE-2026-74967","CVE-2026-74968","CVE-2026-74969","CVE-2026-74970","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74976","CVE-2026-74977","CVE-2026-74978","CVE-2026-74979","CVE-2026-74981","CVE-2026-74982","CVE-2026-74983","CVE-2026-74984","CVE-2026-74985","CVE-2026-74986","CVE-2026-74987","CVE-2026-74988","CVE-2026-74990"]

Threat ID: 6aab495e55bf5e2cf5990ae8

Added to database: 09/17/2026, 01:58:54 UTC

Last updated: 09/17/2026, 01:58:54 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses