FAIL › dossier
firefox
PRODUCT· dossier confidence 67%
Mozilla Firefox, a widely used web browser, has a history of critical security vulnerabilities, including remote code execution and sandbox escapes. The release of publicly available exploit code for recent flaws raises concerns about potential active exploitation and necessitates prompt patching.
PROFILE
CategoryWeb BrowserWhat they doMozilla Firefox is a web browser developed by Mozilla Corporation. It is known for its focus on privacy and customization options.Ownershipprivate
Websitehttps://www.mozilla.org/en-US/ ↗
SECURITY POSTURE
Firefox has a history of critical security vulnerabilities, frequently involving use-after-free and sandbox escape issues. Publicly available exploit code has been released for recent vulnerabilities, indicating a potential risk of active exploitation.
Notable failures
- CVE-2024-9680 (critical RCE)
- CVE-2022-26486 (critical RCE)
- CVE-2022-26485 (critical RCE)
- CVE-2026-14241 (critical RCE)
- CVE-2026-4689 (critical Sandbox escape)
- Public exploit code released for recent vulnerabilities
Patterns: Recurring use-after-free vulnerabilities; Sandbox escape vulnerabilities; Publicly available exploit code
FAILURE HISTORY · 50
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-10-15 | CVE-2024-9680 | critical | Mozilla Firefox contains an actively exploited use-after-free vulnerability in animation timelines that allows remote code execution in the content process. |
| 2022-03-07 | CVE-2022-26486 | high | Mozilla Firefox contained an unpatched use-after-free vulnerability in its WebGPU IPC Framework that allowed arbitrary code execution and was actively exploited in the wild. |
| 2022-03-07 | CVE-2022-26485 | high | Firefox use-after-free flaw in XSLT processing allows remote code execution. |
| 2022-05-25 | CVE-2015-4495 | high | Firefox bypassed Same Origin Policy allowing remote attackers to read arbitrary files or gain privileges. |
| 2022-03-03 | CVE-2013-1675 | high | A Firefox information disclosure vulnerability allowed remote attackers to read sensitive data from process memory via a crafted website. |
| 2026-06-30 | CVE-2026-14241 | critical | Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4. |
| 2026-08-18 | CVE-2026-74943 | critical | CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed |
| 2026-08-18 | CVE-2026-74944 | critical | CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i |
| 2026-08-18 | CVE-2026-74940 | critical | CVE-2026-74940: Use-after-free in the Graphics: Text component. This vulnerability was fixed in |
| 2026-08-18 | CVE-2026-74936 | critical | CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was |
| 2026-06-16 | CVE-2026-12293 | critical | CVE-2026-12293: Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed i |
| 2026-04-07 | CVE-2026-5734 | critical | CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire |
| 2026-04-07 | CVE-2026-5735 | critical | CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t |
| 2026-03-24 | CVE-2026-4689 | critical | CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC |
| 2026-03-24 | CVE-2026-4688 | critical | CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th |
| 2026-03-24 | CVE-2026-4692 | critical | CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f |
| 2026-03-24 | CVE-2026-4691 | critical | CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability |
| 2026-03-24 | CVE-2026-4696 | critical | CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f |
| 2026-03-24 | CVE-2026-4700 | critical | CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe |
| 2026-03-24 | CVE-2026-4698 | critical | CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w |
| 2026-02-24 | CVE-2026-2773 | critical | CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was |
| 2026-02-24 | CVE-2026-2774 | critical | CVE-2026-2774: Integer overflow in the Audio/Video component. This vulnerability was fixed in F |
| 2026-02-24 | CVE-2026-2776 | critical | CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component i |
| 2026-02-24 | CVE-2026-2777 | critical | CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2768 | critical | CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2758 | critical | CVE-2026-2758: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2759 | critical | CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerab |
| 2026-02-24 | CVE-2026-2761 | critical | CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixe |
| 2026-02-24 | CVE-2026-2775 | critical | CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixe |
| 2026-02-24 | CVE-2026-2760 | critical | CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender c |
| 2026-02-24 | CVE-2026-2762 | critical | CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component. This vulnerabili |
| 2026-02-24 | CVE-2026-2763 | critical | CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2764 | critical | CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This |
| 2026-02-24 | CVE-2026-2792 | critical | CVE-2026-2792: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox |
| 2026-02-24 | CVE-2026-2793 | critical | CVE-2026-2793: Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird |
| 2026-02-24 | CVE-2026-2795 | critical | CVE-2026-2795: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2796 | critical | CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability |
| 2026-02-24 | CVE-2026-2797 | critical | CVE-2026-2797: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2799 | critical | CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i |
| 2026-02-24 | CVE-2026-2807 | critical | CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bug |
| 2026-02-24 | CVE-2026-2778 | critical | CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML comp |
| 2026-02-24 | CVE-2026-2757 | critical | CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnera |
| 2026-02-24 | CVE-2026-2766 | critical | CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2765 | critical | CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2772 | critical | CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fi |
| 2026-02-24 | CVE-2026-2771 | critical | CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fix |
| 2026-02-24 | CVE-2026-2770 | critical | CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2767 | critical | CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was |
| 2024-10-09 | CVE-2024-9680 | critical | CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit |
| 2022-12-22 | CVE-2022-26486 | critical | CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free |
DOSSIER SOURCES
- Firefox - Wikipedia · en.wikipedia.org
- Yamazen (TYO:8051) Company Profile & Description - Stock Analysis · stockanalysis.com
- DuckDuckGo - Wikipedia · en.wikipedia.org
- Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship ... · www.techtimes.com
- security flaws Firefox Chrome Adobe VMware Critical Flaws · vulert.com
- Firefox - Wikipedia · en.wikipedia.org
- Home - Brands Owned By · brandsownedby.com
- Firefox: Releases, patches & end-of-life - versio.io · www.versio.io
Open questions: What is the current ownership structure of Mozilla Corporation? · What is the size of the Firefox development team? · What is the extent of the impact of the publicly available exploit code for CVE-2024-9680?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 06:07:46.375107+00:00