Some of these vulnerabilities are listed as known exploited. Update to the latest stable version.
Version security report
Firefox 135 security vulnerabilities
These public CVE records overlap Firefox major version 135. Matching is based on disclosed version ranges, not an exploit test.
562
public CVEs overlapping this major version
- Critical173
- High227
- Medium146
- Low16
CVE list
CVE-2025-2857 Known exploited
Critical CVSS 10.0
Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code.
Fixed in 136.0.4
Critical CVSS 10.0
Sandbox escape due to use-after-free in the Graphics: Canvas2D component.
Fixed in 149
Critical CVSS 10.0
Sandbox escape in the Responsive Design Mode component.
Fixed in 149
Critical CVSS 10.0
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component.
Fixed in 149
Critical CVSS 10.0
Sandbox escape due to use-after-free in the Disability Access APIs component.
Fixed in 149
Critical CVSS 10.0
Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component.
Fixed in 148
Critical CVSS 10.0
Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software.
Fixed in 148
Critical CVSS 10.0
Sandbox escape in the Storage: IndexedDB component.
Fixed in 148
Critical CVSS 10.0
Sandbox escape in the Graphics: WebRender component.
Fixed in 148
Critical CVSS 10.0
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component.
Fixed in 148
Critical CVSS 10.0
Sandbox escape due to invalid pointer in the Disability Access APIs component.
Fixed in 153
Critical CVSS 10.0
Sandbox escape in the Messaging System component.
Fixed in 147
Critical CVSS 9.8
Integer overflow in the Networking: JAR component.
Fixed in 151
Critical CVSS 9.8
Sandbox escape in the Profile Backup component.
Fixed in 150.0.3
Critical CVSS 9.8
Other issue in the WebRTC component.
Fixed in 140.10.2
Critical CVSS 9.8
Incorrect boundary conditions in the Audio/Video: Playback component.
Fixed in 150
Critical CVSS 9.8
Mitigation bypass in the DOM: Security component.
Fixed in 150
Critical CVSS 9.8
Mitigation bypass in the Networking: Cookies component.
Fixed in 150
Critical CVSS 9.8
Mitigation bypass in the Networking: Cookies component.
Fixed in 150
Critical CVSS 9.8
Uninitialized memory in the Audio/Video: Web Codecs component.
Fixed in 150
Critical CVSS 9.8
Memory safety bugs present in Firefox 149.
Fixed in 149.0.2
Critical CVSS 9.8
Memory safety bugs present in Firefox ESR 140.
Fixed in 149.0.2
Critical CVSS 9.8
Memory safety bugs present in Firefox ESR 115.
Fixed in 149.0.2
Critical CVSS 9.8
Memory safety bugs present in Firefox 148 and Thunderbird 148.
Fixed in 149
Critical CVSS 9.8
Use-after-free in the JavaScript Engine component.
Fixed in 149
Critical CVSS 9.8
Memory safety bugs present in Firefox ESR 115.
Fixed in 149
Critical CVSS 9.8
Memory safety bugs present in Firefox ESR 140.
Fixed in 149
Critical CVSS 9.8
Privilege escalation in the Netmonitor component.
Fixed in 149
Critical CVSS 9.8
Use-after-free in the Widget: Cocoa component.
Fixed in 149
Critical CVSS 9.8
Incorrect boundary conditions in the Audio/Video component.
Fixed in 149
Critical CVSS 9.8
Undefined behavior in the WebRTC: Signaling component.
Fixed in 149
Critical CVSS 9.8
JIT miscompilation in the JavaScript Engine component.
Fixed in 149
Critical CVSS 9.8
Use-after-free in the JavaScript Engine component.
Fixed in 149
Critical CVSS 9.8
Mitigation bypass in the Networking: HTTP component.
Fixed in 149
Critical CVSS 9.8
JIT miscompilation in the JavaScript Engine: JIT component.
Fixed in 149
Critical CVSS 9.8
Use-after-free in the Layout: Text and Fonts component.
Fixed in 149
Critical CVSS 9.8
Use-after-free in the CSS Parsing and Computation component.
Fixed in 149
Critical CVSS 9.8
Memory safety bugs present in Firefox 147 and Thunderbird 147.
Fixed in 148
Critical CVSS 9.8
Invalid pointer in the DOM: Core & HTML component.
Fixed in 148
Critical CVSS 9.8
Spoofing issue in the WebAuthn component in Firefox for Android.
Fixed in 148
Critical CVSS 9.8
Use-after-free in the DOM: Core & HTML component.
Fixed in 148
Critical CVSS 9.8
Use-after-free in the JavaScript: GC component.
Fixed in 148
Critical CVSS 9.8
JIT miscompilation in the JavaScript: WebAssembly component.
Fixed in 148
Critical CVSS 9.8
Use-after-free in the JavaScript: GC component.
Fixed in 148
Critical CVSS 9.8
Memory safety bugs present in Firefox ESR 115.
Fixed in 148
Critical CVSS 9.8
Memory safety bugs present in Firefox ESR 140.
Fixed in 148
Critical CVSS 9.8
Mitigation bypass in the Networking: Cache component.
Fixed in 148
Critical CVSS 9.8
Same-origin policy bypass in the Networking: JAR component.
Fixed in 148
Critical CVSS 9.8
Use-after-free in the Graphics: ImageLib component.
Fixed in 148
Critical CVSS 9.8
Incorrect boundary conditions in the Audio/Video: GMP component.
Fixed in 148
Critical CVSS 9.8
Use-after-free in the DOM: Window and Location component.
Fixed in 148
Critical CVSS 9.8
Use-after-free in the JavaScript Engine component.
Fixed in 148
Critical CVSS 9.8
Invalid pointer in the JavaScript Engine component.
Fixed in 148
Critical CVSS 9.8
Mitigation bypass in the DOM: Security component.
Fixed in 148
Critical CVSS 9.8
Privilege escalation in the Netmonitor component.
Fixed in 148
Critical CVSS 9.8
Integer overflow in the Libraries component in NSS.
Fixed in 148
Critical CVSS 9.8
Privilege escalation in the Netmonitor component.
Fixed in 148
Critical CVSS 9.8
Incorrect boundary conditions in the Networking: JAR component.
Fixed in 148
Critical CVSS 9.8
Privilege escalation in the Messaging System component.
Fixed in 148
Critical CVSS 9.8
Mitigation bypass in the DOM: HTML Parser component.
Fixed in 148
Showing the highest-severity 60 of 562 records.