Skip to content
COOEY

FAIL › dossier

firefox

PRODUCT

· dossier confidence 67%

Mozilla Firefox, a widely used web browser, has a history of critical security vulnerabilities, including remote code execution and sandbox escapes. The release of publicly available exploit code for recent flaws raises concerns about potential active exploitation and necessitates prompt patching.

PROFILE
CategoryWeb BrowserWhat they doMozilla Firefox is a web browser developed by Mozilla Corporation. It is known for its focus on privacy and customization options.Ownershipprivate Websitehttps://www.mozilla.org/en-US/ ↗
SECURITY POSTURE

Firefox has a history of critical security vulnerabilities, frequently involving use-after-free and sandbox escape issues. Publicly available exploit code has been released for recent vulnerabilities, indicating a potential risk of active exploitation.

Notable failures
  • CVE-2024-9680 (critical RCE)
  • CVE-2022-26486 (critical RCE)
  • CVE-2022-26485 (critical RCE)
  • CVE-2026-14241 (critical RCE)
  • CVE-2026-4689 (critical Sandbox escape)
  • Public exploit code released for recent vulnerabilities
Patterns: Recurring use-after-free vulnerabilities; Sandbox escape vulnerabilities; Publicly available exploit code
FAILURE HISTORY · 50
DATEEVENTSEVSUMMARY
2024-10-15 CVE-2024-9680 critical Mozilla Firefox contains an actively exploited use-after-free vulnerability in animation timelines that allows remote code execution in the content process.
2022-03-07 CVE-2022-26486 high Mozilla Firefox contained an unpatched use-after-free vulnerability in its WebGPU IPC Framework that allowed arbitrary code execution and was actively exploited in the wild.
2022-03-07 CVE-2022-26485 high Firefox use-after-free flaw in XSLT processing allows remote code execution.
2022-05-25 CVE-2015-4495 high Firefox bypassed Same Origin Policy allowing remote attackers to read arbitrary files or gain privileges.
2022-03-03 CVE-2013-1675 high A Firefox information disclosure vulnerability allowed remote attackers to read sensitive data from process memory via a crafted website.
2026-06-30 CVE-2026-14241 critical Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
2026-08-18 CVE-2026-74943 critical CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed
2026-08-18 CVE-2026-74944 critical CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i
2026-08-18 CVE-2026-74940 critical CVE-2026-74940: Use-after-free in the Graphics: Text component. This vulnerability was fixed in
2026-08-18 CVE-2026-74936 critical CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was
2026-06-16 CVE-2026-12293 critical CVE-2026-12293: Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed i
2026-04-07 CVE-2026-5734 critical CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire
2026-04-07 CVE-2026-5735 critical CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t
2026-03-24 CVE-2026-4689 critical CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC
2026-03-24 CVE-2026-4688 critical CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th
2026-03-24 CVE-2026-4692 critical CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f
2026-03-24 CVE-2026-4691 critical CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability
2026-03-24 CVE-2026-4696 critical CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f
2026-03-24 CVE-2026-4700 critical CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe
2026-03-24 CVE-2026-4698 critical CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
2026-02-24 CVE-2026-2773 critical CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was
2026-02-24 CVE-2026-2774 critical CVE-2026-2774: Integer overflow in the Audio/Video component. This vulnerability was fixed in F
2026-02-24 CVE-2026-2776 critical CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component i
2026-02-24 CVE-2026-2777 critical CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was f
2026-02-24 CVE-2026-2768 critical CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed
2026-02-24 CVE-2026-2758 critical CVE-2026-2758: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
2026-02-24 CVE-2026-2759 critical CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerab
2026-02-24 CVE-2026-2761 critical CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixe
2026-02-24 CVE-2026-2775 critical CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixe
2026-02-24 CVE-2026-2760 critical CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender c
2026-02-24 CVE-2026-2762 critical CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component. This vulnerabili
2026-02-24 CVE-2026-2763 critical CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed
2026-02-24 CVE-2026-2764 critical CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This
2026-02-24 CVE-2026-2792 critical CVE-2026-2792: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox
2026-02-24 CVE-2026-2793 critical CVE-2026-2793: Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird
2026-02-24 CVE-2026-2795 critical CVE-2026-2795: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
2026-02-24 CVE-2026-2796 critical CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability
2026-02-24 CVE-2026-2797 critical CVE-2026-2797: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
2026-02-24 CVE-2026-2799 critical CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i
2026-02-24 CVE-2026-2807 critical CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bug
2026-02-24 CVE-2026-2778 critical CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML comp
2026-02-24 CVE-2026-2757 critical CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnera
2026-02-24 CVE-2026-2766 critical CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was f
2026-02-24 CVE-2026-2765 critical CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed
2026-02-24 CVE-2026-2772 critical CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fi
2026-02-24 CVE-2026-2771 critical CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fix
2026-02-24 CVE-2026-2770 critical CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was f
2026-02-24 CVE-2026-2767 critical CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was
2024-10-09 CVE-2024-9680 critical CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit
2022-12-22 CVE-2022-26486 critical CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free
Open questions: What is the current ownership structure of Mozilla Corporation? · What is the size of the Firefox development team? · What is the extent of the impact of the publicly available exploit code for CVE-2024-9680?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 06:07:46.375107+00:00