BrowserShield

Version security report

Firefox 154 security vulnerabilities

These public CVE records overlap Firefox major version 154. Matching is based on disclosed version ranges, not an exploit test.

237

public CVEs overlapping this major version

CVE list

CVE-2026-75874

Critical CVSS 10.0

Sandbox escape in the Remote Settings Client component.

Fixed in 154

CVE-2026-84143

Critical CVSS 9.8

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.

Fixed in 155

CVE-2026-84142

Critical CVSS 9.8

Internally found bugs present in Thunderbird 154.

Fixed in 155

CVE-2026-84141

Critical CVSS 9.8

Integer overflow in the Graphics: ImageLib component.

Fixed in 155

CVE-2026-84140

Critical CVSS 9.8

Site isolation issue in the DOM: Navigation component.

Fixed in 155

CVE-2026-84134

Critical CVSS 9.8

Other issue in the Profile Backup component.

Fixed in 155

CVE-2026-84133

Critical CVSS 9.8

Site isolation issue in the DOM: Push Subscriptions component.

Fixed in 155

CVE-2026-84129

Critical CVSS 9.8

Site isolation issue in the DOM: Navigation component.

Fixed in 155

CVE-2026-74990

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 140.

Fixed in 154

CVE-2026-74989

Critical CVSS 9.8

Internally found bugs present in Thunderbird 153.

Fixed in 154

CVE-2026-74988

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 153.

Fixed in 154

CVE-2026-74987

Critical CVSS 9.8

Internally found bugs present in Thunderbird ESR 140.

Fixed in 154

CVE-2026-74985

Critical CVSS 9.8

Privilege escalation in the Enterprise Policies component.

Fixed in 154

CVE-2026-74979

Critical CVSS 9.8

Mitigation bypass in the Add-ons Manager component.

Fixed in 154

CVE-2026-74964

Critical CVSS 9.8

Integer overflow in the Graphics component.

Fixed in 154

CVE-2026-74944

Critical CVSS 9.8

Use-after-free in the DOM: Core & HTML component.

Fixed in 154

CVE-2026-74943

Critical CVSS 9.8

Use-after-free in the Graphics: ImageLib component.

Fixed in 154

CVE-2026-74940

Critical CVSS 9.8

Use-after-free in the Graphics: Text component.

Fixed in 154

CVE-2026-74936

Critical CVSS 9.8

Use-after-free in the JavaScript: WebAssembly component.

Fixed in 154

CVE-2026-84121

Critical CVSS 9.6

Sandbox escape due to use-after-free in the DOM: Security component.

Fixed in 155

CVE-2026-84119

Critical CVSS 9.6

Sandbox escape due to use-after-free in the DOM: Navigation component.

Fixed in 155

CVE-2026-74986

Critical CVSS 9.1

Site isolation issue in the CSS Parsing and Computation component.

Fixed in 154

CVE-2026-74961

Critical CVSS 9.1

Side-channel in the Web Audio component.

Fixed in 154

CVE-2026-74959

Critical CVSS 9.1

Mitigation bypass in the Storage: Cache API component.

Fixed in 154

CVE-2026-74956

Critical CVSS 9.1

Same-origin policy bypass in the DOM: Service Workers component.

Fixed in 154

CVE-2026-74938

Critical CVSS 9.1

Mitigation bypass in the JavaScript: GC component.

Fixed in 154

CVE-2026-84131

High CVSS 8.8

Privilege escalation due to invalid pointer in the Graphics component.

Fixed in 155

CVE-2026-84128

High CVSS 8.8

Privilege escalation in the WebDriver BiDi component.

Fixed in 155

CVE-2026-84123

High CVSS 8.8

Privilege escalation due to use-after-free in the Graphics: WebGPU component.

Fixed in 155

CVE-2026-74969

High CVSS 8.8

Use-after-free in the Layout: Text and Fonts component.

Fixed in 154

CVE-2026-74965

High CVSS 8.8

Privilege escalation in the Shell Integration component.

Fixed in 154

CVE-2026-74955

High CVSS 8.8

Privilege escalation in the Request Handling component.

Fixed in 154

CVE-2026-74953

High CVSS 8.8

Privilege escalation in the Networking: Cookies component.

Fixed in 154

CVE-2026-74952

High CVSS 8.8

Privilege escalation in the Application Update component.

Fixed in 154

CVE-2026-74950

High CVSS 8.8

Privilege escalation in the Downloads API component.

Fixed in 154

CVE-2026-74949

High CVSS 8.8

Privilege escalation due to use-after-free in the Graphics: Canvas2D component.

Fixed in 154

CVE-2026-74947

High CVSS 8.8

Privilege escalation due to invalid pointer in the Graphics component.

Fixed in 154

CVE-2026-74946

High CVSS 8.8

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.

Fixed in 154

CVE-2026-74942

High CVSS 8.8

Privilege escalation in the Remote Settings Client component.

Fixed in 154

CVE-2026-74941

High CVSS 8.8

Privilege escalation in the Graphics: CanvasWebGL component.

Fixed in 154

CVE-2026-74939

High CVSS 8.8

Privilege escalation in the DOM: Navigation component.

Fixed in 154

CVE-2026-74937

High CVSS 8.8

Use-after-free in the JavaScript: GC component.

Fixed in 154

CVE-2026-74935

High CVSS 8.8

Privilege escalation in the DOM: Networking component.

Fixed in 154

CVE-2026-74983

High CVSS 8.1

Mitigation bypass in the Data Loss Prevention component.

Fixed in 154

CVE-2026-74981

High CVSS 8.1

Site isolation issue in the Audio/Video: Web Codecs component.

Fixed in 154

CVE-2026-74978

High CVSS 8.1

Clickjacking issue in the Widget component.

Fixed in 154

CVE-2026-74962

High CVSS 8.1

Site isolation issue in the Networking: Cookies component.

Fixed in 154

CVE-2026-74960

High CVSS 8.1

Site isolation issue in the WebExtensions component.

Fixed in 154

CVE-2026-74957

High CVSS 8.1

Mitigation bypass in the Safe Browsing component.

Fixed in 154

CVE-2026-84145

High CVSS 7.5

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.

Fixed in 155

CVE-2026-84144

High CVSS 7.5

Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.

Fixed in 155

CVE-2026-84132

High CVSS 7.5

Information disclosure in the Networking: HTTP component.

Fixed in 155

CVE-2026-84130

High CVSS 7.5

Information disclosure in the Graphics: WebGPU component.

Fixed in 155

CVE-2026-74982

High CVSS 7.5

Denial-of-service in the Widget component.

Fixed in 154

CVE-2026-74977

High CVSS 7.5

Integer overflow in the Graphics component.

Fixed in 154

CVE-2026-74966

High CVSS 7.5

Information disclosure in the Form Autofill component.

Fixed in 154

CVE-2026-74958

High CVSS 7.5

Information disclosure in the WebRTC component.

Fixed in 154

CVE-2026-74954

High CVSS 7.5

Information disclosure due to side-channel in the Storage: Cache API component.

Fixed in 154

CVE-2026-74934

High CVSS 7.5

Site isolation issue in the Graphics: CanvasWebGL component.

Fixed in 154

CVE-2026-92038

High

Mitigation bypass in the Remote Settings Client component

Fixed in 156

Showing the highest-severity 60 of 237 records.

Check my browser