BlackTreeCVE IntelligenceOfficial source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org
Security Vulnerabilities fixed in Firefox 157 — Mozilla
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 14:38 UTC
Linked CVEs50
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-100821Site isolation issue in the Panning and Zooming component
- CVE-2026-100817Other issue in the JavaScript: WebAssembly component
- CVE-2026-100830Mitigation bypass in the DOM: Navigation component
- CVE-2026-100816Site isolation issue in the DOM: Networking component
- CVE-2026-100775Sandbox escape in the Graphics component
- CVE-2026-100810Other issue in the DevTools component
- CVE-2026-100809Same-origin policy bypass in the DevTools component
- CVE-2026-100781Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
- CVE-2026-100787Sandbox escape in the XUL component
- CVE-2026-100828Mitigation bypass in the Bookmarks & History component
- CVE-2026-100829Mitigation bypass in the DOM: Security component
- CVE-2026-100808Mitigation bypass in the DOM: Service Workers component
- CVE-2026-100803Same-origin policy bypass in the WebExtensions component
- CVE-2026-100798Cryptography misuse in Storage: Quota Manager component
- CVE-2026-100794Sandbox escape due to incorrect boundary conditions in the Internationalization component
- CVE-2026-100793JIT miscompilation in the JavaScript Engine component
- CVE-2026-100792JIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-100788Invalid pointer in the JavaScript: WebAssembly component
- CVE-2026-100771Undefined behavior in the DOM: Streams component
- CVE-2026-100763Incorrect boundary conditions in the Graphics: WebGPU component
- CVE-2026-100760Sandbox escape in the Security: Process Sandboxing component
- CVE-2026-100759Uninitialized memory in the Storage: Quota Manager component
- CVE-2026-100823Spoofing issue in the Downloads component in Firefox for Android
- CVE-2026-100822Spoofing issue in the Networking: HTTP component
- CVE-2026-100756Incorrect boundary conditions in the Audio/Video: Playback component
- CVE-2026-100758Sandbox escape in the DOM: Navigation component
- CVE-2026-100831Use-after-free in the DOM: UI Events & Focus Handling component
- CVE-2026-100826Denial-of-service in the Storage: StorageManager component
- CVE-2026-100825Use-after-free in the JavaScript Engine: JIT component
- CVE-2026-100824Privilege escalation in the Places component
- CVE-2026-100815Use-after-free in the CSS Parsing and Computation component
- CVE-2026-100814Incorrect boundary conditions in the JavaScript Engine: JIT component
- CVE-2026-100812Denial-of-service in the Graphics component
- CVE-2026-100806Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100800Sandbox escape due to use-after-free in the Disability Access APIs component
- CVE-2026-100765Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100820Privilege escalation in the Address Bar component
- CVE-2026-100819Sandbox escape due to incorrect boundary conditions in the XPCOM component
- CVE-2026-100818Sandbox escape due to use-after-free in the Widget: Gtk component
- CVE-2026-100811Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100807Privilege escalation in the DOM: Service Workers component
- CVE-2026-100801Privilege escalation in the DLL Services component
- CVE-2026-100797Privilege escalation due to use-after-free in the Graphics: WebRender component
- CVE-2026-96869Information disclosure in the Networking component
- CVE-2026-100791Use-after-free in the DOM: Core & HTML component
- CVE-2026-100790Use-after-free in the XSLT component
- CVE-2026-100789Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100786Sandbox escape due to use-after-free in the Graphics component
- CVE-2026-100785Use-after-free in the DOM: Core & HTML component
- CVE-2026-100784Use-after-free in the Layout: Text and Fonts component
Source and provenance
Original title: Security Vulnerabilities fixed in Firefox 157 — Mozilla. Captured 29 Sept 2026, 14:38 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗