BrowserShield

Version security report

Firefox 157 security vulnerabilities

These public CVE records overlap Firefox major version 157. Matching is based on disclosed version ranges, not an exploit test.

77

public CVEs overlapping this major version

CVE list

CVE-2026-100793

High

JIT miscompilation in the JavaScript Engine component

Fixed in 157

CVE-2026-100792

High

JIT miscompilation in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100791

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100789

High

Use-after-free in the Graphics: Canvas2D component

Fixed in 157

CVE-2026-100788

High

Invalid pointer in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100786

High

Sandbox escape due to use-after-free in the Graphics component

Fixed in 157

CVE-2026-100785

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100784

High

Use-after-free in the Layout: Text and Fonts component

Fixed in 157

CVE-2026-100783

High

Uninitialized memory in the Audio/Video component

Fixed in 157

CVE-2026-100782

High

Privilege escalation due to incorrect boundary conditions in the Graphics component

Fixed in 157

CVE-2026-100781

High

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component

Fixed in 157

CVE-2026-100780

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100778

High

Sandbox escape due to use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100777

High

Use-after-free in the Graphics: Canvas2D component

Fixed in 157

CVE-2026-100776

High

Use-after-free in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100774

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100773

High

Use-after-free in the Storage: IndexedDB component

Fixed in 157

CVE-2026-100772

High

Use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100771

High

Undefined behavior in the DOM: Streams component

Fixed in 157

CVE-2026-100770

High

Sandbox escape due to use-after-free in the DOM: Content Processes component

Fixed in 157

CVE-2026-100769

High

Use-after-free in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100768

High

Use-after-free in the Graphics: WebGPU component

Fixed in 157

CVE-2026-100767

High

Use-after-free in the Networking: Cache component

Fixed in 157

CVE-2026-100766

High

Information disclosure in the Networking: JAR component

Fixed in 157

CVE-2026-100765

High

Use-after-free in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100764

High

Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component

Fixed in 157

CVE-2026-100763

High

Incorrect boundary conditions in the Graphics: WebGPU component

Fixed in 157

CVE-2026-100762

High

Sandbox escape due to use-after-free in the DOM: Content Processes component

Fixed in 157

CVE-2026-100761

High

Privilege escalation due to use-after-free in the Graphics: WebGPU component

Fixed in 157

CVE-2026-100760

High

Sandbox escape in the Security: Process Sandboxing component

Fixed in 157

CVE-2026-100759

High

Uninitialized memory in the Storage: Quota Manager component

Fixed in 157

CVE-2026-100758

High

Sandbox escape in the DOM: Navigation component

Fixed in 157

CVE-2026-100756

High

Incorrect boundary conditions in the Audio/Video: Playback component

Fixed in 157

CVE-2024-0953

Medium CVSS 6.1

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code.

CVE-2026-96869

Medium

Information disclosure in the Networking component

Fixed in 157

CVE-2026-100821

Medium

Site isolation issue in the Panning and Zooming component

Fixed in 157

CVE-2026-100820

Medium

Privilege escalation in the Address Bar component

Fixed in 157

CVE-2026-100819

Medium

Sandbox escape due to incorrect boundary conditions in the XPCOM component

Fixed in 157

CVE-2026-100818

Medium

Sandbox escape due to use-after-free in the Widget: Gtk component

Fixed in 157

CVE-2026-100817

Medium

Other issue in the JavaScript: WebAssembly component

Fixed in 157

CVE-2026-100816

Medium

Site isolation issue in the DOM: Networking component

Fixed in 157

CVE-2026-100815

Medium

Use-after-free in the CSS Parsing and Computation component

Fixed in 157

CVE-2026-100814

Medium

Incorrect boundary conditions in the JavaScript Engine: JIT component

Fixed in 157

CVE-2026-100813

Medium

Invalid pointer in the JavaScript Engine: JIT component

Fixed in 157

CVE-2026-100812

Medium

Denial-of-service in the Graphics component

Fixed in 157

CVE-2026-100811

Medium

Sandbox escape due to use-after-free in the DOM: Core & HTML component

Fixed in 157

CVE-2026-100809

Medium

Same-origin policy bypass in the DevTools component

Fixed in 157

CVE-2026-100808

Medium

Mitigation bypass in the DOM: Service Workers component

Fixed in 157

CVE-2026-100807

Medium

Privilege escalation in the DOM: Service Workers component

Fixed in 157

CVE-2026-100806

Medium

Uninitialized memory in the Graphics: WebGPU component

Fixed in 157

CVE-2026-100805

Medium

Race condition, use-after-free in the Audio/Video component

Fixed in 157

CVE-2026-100804

Medium

Sandbox escape due to use-after-free in the Preferences: Backend component

Fixed in 157

CVE-2026-100803

Medium

Same-origin policy bypass in the WebExtensions component

Fixed in 157

CVE-2026-100802

Medium

Uninitialized memory in the Graphics: WebGPU component

Fixed in 157

Showing the highest-severity 60 of 77 records.

Check my browser