BlackTreeCVE IntelligenceOfficial source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org
Security Vulnerabilities fixed in Firefox 153 — Mozilla
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 08:30 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-16371Privilege escalation in the DOM: Navigation component
- CVE-2026-16365Privilege escalation in the DOM: Workers component
- CVE-2026-16389Incorrect boundary conditions, integer overflow in the Libraries component in NSS
- CVE-2026-16392JIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-16366Privilege escalation in the DOM: Navigation component
- CVE-2026-16379Privilege escalation in the DOM: Content Processes component
- CVE-2026-16372Privilege escalation in the DOM: Content Processes component
- CVE-2026-16396Privilege escalation in WebExtensions
- CVE-2026-16401Privilege escalation in the Data Loss Prevention component
- CVE-2026-16360Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153
- CVE-2026-16412Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153
- CVE-2026-16411Memory safety bugs fixed in Firefox 153
- CVE-2026-16409Invalid pointer in the Security: PSM component
- CVE-2026-16398Site isolation issue in the Graphics component
- CVE-2026-16395Integer overflow in the Audio/Video component
- CVE-2026-16364Incorrect boundary conditions in the Audio/Video: Playback component
- CVE-2026-16410JIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-16408Integer overflow in the Audio/Video: Playback component
- CVE-2026-16407Mitigation bypass in the DOM: Service Workers component
- CVE-2026-16406Mitigation bypass in the Networking component
- CVE-2026-16405Information disclosure in the Networking: WebSockets component
- CVE-2026-16403Spoofing issue in the Address Bar component
- CVE-2026-16402Integer overflow in the Graphics: ImageLib component
- CVE-2026-16400Information disclosure in the DOM: Security component
- CVE-2026-16399Site isolation issue in the DOM: Navigation component
- CVE-2026-16394Mitigation bypass in the DOM: Security component
- CVE-2026-16359Incorrect boundary conditions in the Audio/Video: GMP component
- CVE-2026-16393Incorrect boundary conditions in the Graphics: WebGPU component
- CVE-2026-16391Information disclosure in the Storage: IndexedDB component
- CVE-2026-16390Mitigation bypass in the Enterprise Policies component
- CVE-2026-16388Sandbox escape in the DOM: Networking component
- CVE-2026-16387Site isolation issue in the Networking component
- CVE-2026-16386Information disclosure due to uninitialized memory in the Graphics: WebGPU component
- CVE-2026-16385Information disclosure due to uninitialized memory in the Graphics: WebGPU component
- CVE-2026-16384Information disclosure due to uninitialized memory in the Graphics: WebGPU component
- CVE-2026-16383Mitigation bypass in the DOM: Networking component
- CVE-2026-16382Mitigation bypass in the DOM: Service Workers component
- CVE-2026-16381Same-origin policy bypass in the Networking: DNS component
- CVE-2026-16380Mitigation bypass in the Networking component
- CVE-2026-16358Site isolation issue in the Graphics: WebRender component
- CVE-2026-16378Other issue in the DOM: Copy & Paste and Drag & Drop component
- CVE-2026-16377Mitigation bypass in the PDF Viewer component
- CVE-2026-16376Denial-of-service in the Graphics: WebGPU component
- CVE-2026-16375Site isolation issue in the Networking: HTTP component
- CVE-2026-16374Information disclosure in the Framework component in DevTools
- CVE-2026-16370Mitigation bypass in the DOM: Networking component
- CVE-2026-16357Incorrect boundary conditions in the Graphics component
- CVE-2026-16356Sandbox escape due to use-after-free in the Disability Access APIs component
- CVE-2026-16355JIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-16369Integer overflow in the JavaScript: WebAssembly component
Source and provenance
Original title: Security Vulnerabilities fixed in Firefox 153 — Mozilla. Captured 27 Sept 2026, 08:30 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗