BrowserShield

Version security report

Firefox 156 security vulnerabilities

These public CVE records overlap Firefox major version 156. Matching is based on disclosed version ranges, not an exploit test.

150

public CVEs overlapping this major version

CVE list

CVE-2026-92038

High

Mitigation bypass in the Remote Settings Client component

Fixed in 156

CVE-2026-92037

High

Incorrect boundary conditions in the DOM: Animation component

Fixed in 156

CVE-2026-92036

High

Incorrect boundary conditions in the Networking: HTTP component

Fixed in 156

CVE-2026-92035

High

Sandbox escape due to incorrect boundary conditions in the Graphics component

Fixed in 156

CVE-2026-92034

High

Site isolation issue in the Graphics component

Fixed in 156

CVE-2026-92033

High

Privilege escalation in Firefox for Android

Fixed in 156

CVE-2026-92028

High

Use-after-free in the DOM: Core & HTML component

Fixed in 156

CVE-2026-92027

High

Use-after-free in the DOM: Streams component

Fixed in 156

CVE-2026-92026

High

Use-after-free in the Networking component

Fixed in 156

CVE-2026-92025

High

Use-after-free in the DOM: Navigation component

Fixed in 156

CVE-2026-92022

High

Use-after-free in the DOM: HTML Parser component

Fixed in 156

CVE-2026-92020

High

Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component

Fixed in 156

CVE-2026-92019

High

Mitigation bypass in the Remote Settings Client component

Fixed in 156

CVE-2026-92018

High

Sandbox escape in the DOM: Core & HTML component

Fixed in 156

CVE-2026-92017

High

Privilege escalation in the DOM: Service Workers component

Fixed in 156

CVE-2026-92016

High

Use-after-free in the Disability Access APIs component

Fixed in 156

CVE-2026-92015

High

Privilege escalation in the WebExtensions component

Fixed in 156

CVE-2026-92013

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 156

CVE-2026-92012

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 156

CVE-2026-92011

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 156

CVE-2026-92010

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 156

CVE-2026-92009

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 156

CVE-2026-92008

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 156

CVE-2026-92007

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 156

CVE-2026-92006

High

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Fixed in 156

CVE-2026-92005

High

Use-after-free in the Audio/Video: Web Codecs component

Fixed in 156

CVE-2026-100793

High

JIT miscompilation in the JavaScript Engine component

Fixed in 157

CVE-2026-100792

High

JIT miscompilation in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100791

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100789

High

Use-after-free in the Graphics: Canvas2D component

Fixed in 157

CVE-2026-100788

High

Invalid pointer in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100786

High

Sandbox escape due to use-after-free in the Graphics component

Fixed in 157

CVE-2026-100785

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100784

High

Use-after-free in the Layout: Text and Fonts component

Fixed in 157

CVE-2026-100783

High

Uninitialized memory in the Audio/Video component

Fixed in 157

CVE-2026-100782

High

Privilege escalation due to incorrect boundary conditions in the Graphics component

Fixed in 157

CVE-2026-100781

High

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component

Fixed in 157

CVE-2026-100780

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100778

High

Sandbox escape due to use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100777

High

Use-after-free in the Graphics: Canvas2D component

Fixed in 157

CVE-2026-100776

High

Use-after-free in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100774

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100773

High

Use-after-free in the Storage: IndexedDB component

Fixed in 157

CVE-2026-100772

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100771

High

Undefined behavior in the DOM: Streams component

Fixed in 157

CVE-2026-100770

High

Sandbox escape due to use-after-free in the DOM: Content Processes component

Fixed in 157

CVE-2026-100769

High

Use-after-free in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100768

High

Use-after-free in the Graphics: WebGPU component

Fixed in 157

CVE-2026-100767

High

Use-after-free in the Networking: Cache component

Fixed in 157

CVE-2026-100766

High

Information disclosure in the Networking: JAR component

Fixed in 157

CVE-2026-100765

High

Use-after-free in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100764

High

Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component

Fixed in 157

CVE-2026-100763

High

Incorrect boundary conditions in the Graphics: WebGPU component

Fixed in 157

Showing the highest-severity 60 of 150 records.

Check my browser