BrowserShield

Version security report

Firefox 153 security vulnerabilities

These public CVE records overlap Firefox major version 153. Matching is based on disclosed version ranges, not an exploit test.

123

public CVEs overlapping this major version

CVE list

CVE-2026-16367

Critical CVSS 10.0

Sandbox escape due to invalid pointer in the Disability Access APIs component.

Fixed in 153

CVE-2026-16412

Critical CVSS 9.8

Memory safety bugs present in Firefox ESR 140.

Fixed in 153

CVE-2026-16411

Critical CVSS 9.8

Memory safety bugs present in Firefox 152.

Fixed in 153

CVE-2026-16410

Critical CVSS 9.8

JIT miscompilation in the JavaScript Engine: JIT component.

Fixed in 153

CVE-2026-16408

Critical CVSS 9.8

Integer overflow in the Audio/Video: Playback component.

Fixed in 153

CVE-2026-16407

Critical CVSS 9.8

Mitigation bypass in the DOM: Service Workers component.

Fixed in 153

CVE-2026-16402

Critical CVSS 9.8

Integer overflow in the Graphics: ImageLib component.

Fixed in 153

CVE-2026-16395

Critical CVSS 9.8

Integer overflow in the Audio/Video component.

Fixed in 153

CVE-2026-16389

Critical CVSS 9.8

Incorrect boundary conditions, integer overflow in the Libraries component in NSS.

Fixed in 153

CVE-2026-16388

Critical CVSS 9.8

Sandbox escape in the DOM: Networking component.

Fixed in 153

CVE-2026-16387

Critical CVSS 9.8

Site isolation issue in the Networking component.

Fixed in 153

CVE-2026-16383

Critical CVSS 9.8

Mitigation bypass in the DOM: Networking component.

Fixed in 153

CVE-2026-16382

Critical CVSS 9.8

Mitigation bypass in the DOM: Service Workers component.

Fixed in 153

CVE-2026-16377

Critical CVSS 9.8

Mitigation bypass in the PDF Viewer component.

Fixed in 153

CVE-2026-16375

Critical CVSS 9.8

Site isolation issue in the Networking: HTTP component.

Fixed in 153

CVE-2026-16369

Critical CVSS 9.8

Integer overflow in the JavaScript: WebAssembly component.

Fixed in 153

CVE-2026-16368

Critical CVSS 9.8

Incorrect boundary conditions in the JavaScript: WebAssembly component.

Fixed in 153

CVE-2026-16363

Critical CVSS 9.8

JIT miscompilation in the JavaScript: WebAssembly component.

Fixed in 153

CVE-2026-16360

Critical CVSS 9.8

Memory safety bugs present in Firefox ESR 115.

Fixed in 153

CVE-2026-16358

Critical CVSS 9.8

Site isolation issue in the Graphics: WebRender component.

Fixed in 153

CVE-2026-16357

Critical CVSS 9.8

Incorrect boundary conditions in the Graphics component.

Fixed in 153

CVE-2026-16356

Critical CVSS 9.8

Sandbox escape due to use-after-free in the Disability Access APIs component.

Fixed in 153

CVE-2026-16355

Critical CVSS 9.8

JIT miscompilation in the JavaScript Engine: JIT component.

Fixed in 153

CVE-2026-16353

Critical CVSS 9.8

Invalid pointer in the DOM: Bindings (WebIDL) component.

Fixed in 153

CVE-2026-16352

Critical CVSS 9.8

Sandbox escape due to use-after-free in the Disability Access APIs component.

Fixed in 153

CVE-2026-16351

Critical CVSS 9.8

Sandbox escape due to use-after-free in the DOM: Navigation component.

Fixed in 153

CVE-2026-16350

Critical CVSS 9.8

Incorrect boundary conditions in the Audio/Video: cubeb component.

Fixed in 153

CVE-2026-16349

Critical CVSS 9.8

Same-origin policy bypass in the DOM: Navigation component.

Fixed in 153

CVE-2026-16406

Critical CVSS 9.1

Mitigation bypass in the Networking component.

Fixed in 153

CVE-2026-16394

Critical CVSS 9.1

Mitigation bypass in the DOM: Security component.

Fixed in 153

CVE-2026-16393

Critical CVSS 9.1

Incorrect boundary conditions in the Graphics: WebGPU component.

Fixed in 153

CVE-2026-16392

Critical CVSS 9.1

JIT miscompilation in the JavaScript Engine: JIT component.

Fixed in 153

CVE-2026-16390

Critical CVSS 9.1

Mitigation bypass in the Enterprise Policies component.

Fixed in 153

CVE-2026-16381

Critical CVSS 9.1

Same-origin policy bypass in the Networking: DNS component.

Fixed in 153

CVE-2026-16380

Critical CVSS 9.1

Mitigation bypass in the Networking component.

Fixed in 153

CVE-2026-16370

Critical CVSS 9.1

Mitigation bypass in the DOM: Networking component.

Fixed in 153

CVE-2026-16364

Critical CVSS 9.1

Incorrect boundary conditions in the Audio/Video: Playback component.

Fixed in 153

CVE-2026-16359

Critical CVSS 9.1

Incorrect boundary conditions in the Audio/Video: GMP component.

Fixed in 153

CVE-2026-16401

High CVSS 8.8

Privilege escalation in the Data Loss Prevention component.

Fixed in 153

CVE-2026-16396

High CVSS 8.8

Privilege escalation in WebExtensions.

Fixed in 153

CVE-2026-16379

High CVSS 8.8

Privilege escalation in the DOM: Content Processes component.

Fixed in 153

CVE-2026-16372

High CVSS 8.8

Privilege escalation in the DOM: Content Processes component.

Fixed in 153

CVE-2026-16371

High CVSS 8.8

Privilege escalation in the DOM: Navigation component.

Fixed in 153

CVE-2026-16366

High CVSS 8.8

Privilege escalation in the DOM: Navigation component.

Fixed in 153

CVE-2026-16365

High CVSS 8.8

Privilege escalation in the DOM: Workers component.

Fixed in 153

CVE-2026-16362

High CVSS 8.8

Use-after-free in the WebRTC: Audio/Video component.

Fixed in 153

CVE-2026-16409

High CVSS 7.5

Invalid pointer in the Security: PSM component.

Fixed in 153

CVE-2026-16405

High CVSS 7.5

Information disclosure in the Networking: WebSockets component.

Fixed in 153

CVE-2026-16400

High CVSS 7.5

Information disclosure in the DOM: Security component.

Fixed in 153

CVE-2026-16399

High CVSS 7.5

Site isolation issue in the DOM: Navigation component.

Fixed in 153

CVE-2026-16398

High CVSS 7.5

Site isolation issue in the Graphics component.

Fixed in 153

CVE-2026-16391

High CVSS 7.5

Information disclosure in the Storage: IndexedDB component.

Fixed in 153

CVE-2026-16386

High CVSS 7.5

Information disclosure due to uninitialized memory in the Graphics: WebGPU component.

Fixed in 153

CVE-2026-16385

High CVSS 7.5

Information disclosure due to uninitialized memory in the Graphics: WebGPU component.

Fixed in 153

CVE-2026-16384

High CVSS 7.5

Information disclosure due to uninitialized memory in the Graphics: WebGPU component.

Fixed in 153

CVE-2026-16378

High CVSS 7.5

Other issue in the DOM: Copy & Paste and Drag & Drop component.

Fixed in 153

CVE-2026-16376

High CVSS 7.5

Denial-of-service in the Graphics: WebGPU component.

Fixed in 153

CVE-2026-16374

High CVSS 7.5

Information disclosure in the Framework component in DevTools.

Fixed in 153

CVE-2026-16354

High CVSS 7.5

Information disclosure in the Graphics: ImageLib component.

Fixed in 153

CVE-2026-75874

High

Sandbox escape in the Remote Settings Client component

Fixed in 154

Showing the highest-severity 60 of 123 records.

Check my browser