FAIL › dossier
firefox
PRODUCT· dossier confidence 67%
Mozilla Firefox, a widely used web browser, has a history of critical security vulnerabilities, including remote code execution and sandbox escapes. The release of publicly available exploit code for recent flaws raises concerns about potential active exploitation and necessitates prompt patching.
PROFILE
CategoryWeb BrowserWhat they doMozilla Firefox is a web browser developed by Mozilla Corporation. It is known for its focus on privacy and customization options.Ownershipprivate
Websitehttps://www.mozilla.org/en-US/ ↗
SECURITY POSTURE
Firefox has a history of critical security vulnerabilities, frequently involving use-after-free and sandbox escape issues. Publicly available exploit code has been released for recent vulnerabilities, indicating a potential risk of active exploitation.
Notable failures
- CVE-2024-9680 (critical RCE)
- CVE-2022-26486 (critical RCE)
- CVE-2022-26485 (critical RCE)
- CVE-2026-14241 (critical RCE)
- CVE-2026-4689 (critical Sandbox escape)
- Public exploit code released for recent vulnerabilities
Patterns: Recurring use-after-free vulnerabilities; Sandbox escape vulnerabilities; Publicly available exploit code
FAILURE HISTORY · 54
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-10-15 | CVE-2024-9680 | critical | Mozilla Firefox contains an actively exploited use-after-free vulnerability in animation timelines that allows remote code execution in the content process. |
| 2022-03-07 | CVE-2022-26485 | high | Firefox use-after-free flaw in XSLT processing allows remote code execution. |
| 2022-03-07 | CVE-2022-26486 | high | Mozilla Firefox contained an unpatched use-after-free vulnerability in its WebGPU IPC Framework that allowed arbitrary code execution and was actively exploited in the wild. |
| 2026-08-18 | CVE-2026-74940 | critical | Mozilla Firefox and Thunderbird suffered a critical use-after-free vulnerability in the Graphics: Text component, patched in versions 154 and ESR 115.39. |
| 2022-05-25 | CVE-2015-4495 | high | Firefox bypassed Same Origin Policy allowing remote attackers to read arbitrary files or gain privileges. |
| 2026-09-01 | CVE-2026-84140 | critical | Mozilla Firefox had a critical site isolation DOM navigation vulnerability fixed in Firefox 155 and ESR 153.2. |
| 2026-09-01 | CVE-2026-84142 | critical | Mozilla Thunderbird 154 contained internally found memory corruption bugs that could have been exploited, fixed in version 155. |
| 2026-09-01 | CVE-2026-84143 | critical | Mozilla Thunderbird 154 and earlier versions contained internally found memory corruption bugs that could have been exploited. |
| 2026-08-18 | CVE-2026-74936 | critical | Mozilla's Firefox and Thunderbird contained a critical use-after-free vulnerability in the WebAssembly component that was patched in version 154. |
| 2026-08-18 | CVE-2026-74944 | critical | Mozilla Firefox and Thunderbird contained a critical use-after-free vulnerability in the DOM component that was patched in versions 154 and 140.14. |
| 2026-08-18 | CVE-2026-74943 | critical | Mozilla fixed a critical use-after-free vulnerability in Firefox and Thunderbird's ImageLib component. |
| 2022-03-03 | CVE-2013-1675 | high | A Firefox information disclosure vulnerability allowed remote attackers to read sensitive data from process memory via a crafted website. |
| 2026-06-30 | CVE-2026-14241 | critical | Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4. |
| 2026-09-01 | CVE-2026-84141 | critical | Mozilla Firefox had an integer overflow vulnerability in its ImageLib component that was patched in Firefox 155 and Firefox ESR 153.2. |
| 2026-06-16 | CVE-2026-12293 | critical | CVE-2026-12293: Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed i |
| 2026-04-07 | CVE-2026-5735 | critical | CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t |
| 2026-04-07 | CVE-2026-5734 | critical | CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire |
| 2026-03-24 | CVE-2026-4700 | critical | CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe |
| 2026-03-24 | CVE-2026-4698 | critical | CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w |
| 2026-03-24 | CVE-2026-4696 | critical | CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f |
| 2026-03-24 | CVE-2026-4692 | critical | CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f |
| 2026-03-24 | CVE-2026-4688 | critical | CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th |
| 2026-03-24 | CVE-2026-4689 | critical | CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC |
| 2026-03-24 | CVE-2026-4691 | critical | CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability |
| 2026-02-24 | CVE-2026-2796 | critical | CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability |
| 2026-02-24 | CVE-2026-2799 | critical | CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i |
| 2026-02-24 | CVE-2026-2807 | critical | CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bug |
| 2026-02-24 | CVE-2026-2778 | critical | CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML comp |
| 2026-02-24 | CVE-2026-2757 | critical | CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnera |
| 2026-02-24 | CVE-2026-2766 | critical | CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2765 | critical | CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2772 | critical | CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fi |
| 2026-02-24 | CVE-2026-2771 | critical | CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fix |
| 2026-02-24 | CVE-2026-2770 | critical | CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2767 | critical | CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was |
| 2026-02-24 | CVE-2026-2773 | critical | CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was |
| 2026-02-24 | CVE-2026-2774 | critical | CVE-2026-2774: Integer overflow in the Audio/Video component. This vulnerability was fixed in F |
| 2026-02-24 | CVE-2026-2775 | critical | CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixe |
| 2026-02-24 | CVE-2026-2776 | critical | CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component i |
| 2026-02-24 | CVE-2026-2777 | critical | CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2768 | critical | CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2758 | critical | CVE-2026-2758: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2759 | critical | CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerab |
| 2026-02-24 | CVE-2026-2761 | critical | CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixe |
| 2026-02-24 | CVE-2026-2795 | critical | CVE-2026-2795: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2797 | critical | CVE-2026-2797: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2760 | critical | CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender c |
| 2026-02-24 | CVE-2026-2762 | critical | CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component. This vulnerabili |
| 2026-02-24 | CVE-2026-2763 | critical | CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2764 | critical | CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This |
| 2026-02-24 | CVE-2026-2792 | critical | CVE-2026-2792: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox |
| 2026-02-24 | CVE-2026-2793 | critical | CVE-2026-2793: Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird |
| 2024-10-09 | CVE-2024-9680 | critical | CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit |
| 2022-12-22 | CVE-2022-26486 | critical | CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free |
DOSSIER SOURCES
- Firefox - Wikipedia · en.wikipedia.org
- Yamazen (TYO:8051) Company Profile & Description - Stock Analysis · stockanalysis.com
- DuckDuckGo - Wikipedia · en.wikipedia.org
- Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship ... · www.techtimes.com
- security flaws Firefox Chrome Adobe VMware Critical Flaws · vulert.com
- Firefox - Wikipedia · en.wikipedia.org
- Home - Brands Owned By · brandsownedby.com
- Firefox: Releases, patches & end-of-life - versio.io · www.versio.io
Open questions: What is the current ownership structure of Mozilla Corporation? · What is the size of the Firefox development team? · What is the extent of the impact of the publicly available exploit code for CVE-2024-9680?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 06:07:46.375107+00:00