BrowserShield

Version security report

Firefox 154 security vulnerabilities

These public CVE records overlap Firefox major version 154. Matching is based on disclosed version ranges, not an exploit test.

59

public CVEs overlapping this major version

CVE list

CVE-2026-75874

High

Sandbox escape in the Remote Settings Client component

Fixed in 154

CVE-2026-74990

High

Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Fixed in 154

CVE-2026-74988

High

Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154

Fixed in 154

CVE-2026-74987

High

Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154

Fixed in 154

CVE-2026-74949

High

Privilege escalation due to use-after-free in the Graphics: Canvas2D component

Fixed in 154

CVE-2026-74948

High

Information disclosure in the Graphics component

Fixed in 154

CVE-2026-74947

High

Privilege escalation due to invalid pointer in the Graphics component

Fixed in 154

CVE-2026-74946

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 154

CVE-2026-74945

High

Information disclosure in the Graphics: Text component

Fixed in 154

CVE-2026-74944

High

Use-after-free in the DOM: Core & HTML component

Fixed in 154

CVE-2026-74943

High

Use-after-free in the Graphics: ImageLib component

Fixed in 154

CVE-2026-74942

High

Privilege escalation in the Remote Settings Client component

Fixed in 154

CVE-2026-74941

High

Privilege escalation in the Graphics: CanvasWebGL component

Fixed in 154

CVE-2026-74940

High

Use-after-free in the Graphics: Text component

Fixed in 154

CVE-2026-74939

High

Privilege escalation in the DOM: Navigation component

Fixed in 154

CVE-2026-74938

High

Mitigation bypass in the JavaScript: GC component

Fixed in 154

CVE-2026-74937

High

Use-after-free in the JavaScript: GC component

Fixed in 154

CVE-2026-74936

High

Use-after-free in the JavaScript: WebAssembly component

Fixed in 154

CVE-2026-74935

High

Privilege escalation in the DOM: Networking component

Fixed in 154

CVE-2026-74934

High

Site isolation issue in the Graphics: CanvasWebGL component

Fixed in 154

CVE-2024-0953

Medium CVSS 6.1

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code.

CVE-2026-74989

Medium

Internally found bugs fixed in Firefox 154

Fixed in 154

CVE-2026-74974

Medium

Same-origin policy bypass in the Graphics: ImageLib component

Fixed in 154

CVE-2026-74973

Medium

Race condition, use-after-free in the Graphics component

Fixed in 154

CVE-2026-74972

Medium

Information disclosure in the DOM: Push Subscriptions component

Fixed in 154

CVE-2026-74971

Medium

Information disclosure in the DOM: UI Events & Focus Handling component

Fixed in 154

CVE-2026-74970

Medium

Site isolation issue in the Graphics component

Fixed in 154

CVE-2026-74969

Medium

Use-after-free in the Layout: Text and Fonts component

Fixed in 154

CVE-2026-74968

Medium

Site isolation issue in the Graphics: WebRender component

Fixed in 154

CVE-2026-74967

Medium

Same-origin policy bypass in the Audio/Video: Playback component

Fixed in 154

CVE-2026-74966

Medium

Information disclosure in the Form Autofill component

Fixed in 154

CVE-2026-74965

Medium

Privilege escalation in the Shell Integration component

Fixed in 154

CVE-2026-74964

Medium

Integer overflow in the Graphics component

Fixed in 154

CVE-2026-74963

Medium

Same-origin policy bypass in the Networking: Cookies component

Fixed in 154

CVE-2026-74962

Medium

Site isolation issue in the Networking: Cookies component

Fixed in 154

CVE-2026-74961

Medium

Side-channel in the Web Audio component

Fixed in 154

CVE-2026-74960

Medium

Site isolation issue in the WebExtensions component

Fixed in 154

CVE-2026-74959

Medium

Mitigation bypass in the Storage: Cache API component

Fixed in 154

CVE-2026-74958

Medium

Information disclosure in the WebRTC component

Fixed in 154

CVE-2026-74957

Medium

Mitigation bypass in the Safe Browsing component

Fixed in 154

CVE-2026-74956

Medium

Same-origin policy bypass in the DOM: Service Workers component

Fixed in 154

CVE-2026-74955

Medium

Privilege escalation in the Request Handling component

Fixed in 154

CVE-2026-74954

Medium

Information disclosure due to side-channel in the Storage: Cache API component

Fixed in 154

CVE-2026-74953

Medium

Privilege escalation in the Networking: Cookies component

Fixed in 154

CVE-2026-74952

Medium

Privilege escalation in the Application Update component

Fixed in 154

CVE-2026-74951

Medium

Clickjacking issue in Firefox for Android

Fixed in 154

CVE-2026-74950

Medium

Privilege escalation in the Downloads API component

Fixed in 154

CVE-2026-74986

Low

Site isolation issue in the CSS Parsing and Computation component

Fixed in 154

CVE-2026-74985

Low

Privilege escalation in the Enterprise Policies component

Fixed in 154

CVE-2026-74984

Low

Race condition in the JavaScript Engine component

Fixed in 154

CVE-2026-74983

Low

Mitigation bypass in the Data Loss Prevention component

Fixed in 154

CVE-2026-74982

Low

Denial-of-service in the Widget component

Fixed in 154

CVE-2026-74981

Low

Site isolation issue in the Audio/Video: Web Codecs component

Fixed in 154

CVE-2026-74980

Low

Clickjacking issue in the Downloads component in Firefox for Android

Fixed in 154

CVE-2026-74979

Low

Mitigation bypass in the Add-ons Manager component

Fixed in 154

CVE-2026-74978

Low

Clickjacking issue in the Widget component

Fixed in 154

CVE-2026-74977

Low

Integer overflow in the Graphics component

Fixed in 154

CVE-2026-74976

Low

JIT miscompilation in the JavaScript Engine: JIT component

Fixed in 154

CVE-2026-74975

Low

Spoofing issue in the Downloads component in Firefox for Android

Fixed in 154

Check my browser