Skip to content
COOEY

FAIL › dossier

mozilla

VENDOR

· dossier confidence 40%

Mozilla is a nonprofit-backed vendor of the Firefox browser and Thunderbird email client with a strong open-source security program, but its internal failure history reveals a chronic pattern of critical memory safety, use-after-free, and sandbox escape vulnerabilities that require urgent patches and expose users to remote code execution and privilege escalation.

PROFILE
Categorysoftware vendorWhat they doMozilla develops the Firefox web browser, Thunderbird email client, and related open-source software, operating as a nonprofit-backed technology organization focused on internet privacy and user choice.Ownershipnonprofit-backed Websitehttps://www.mozilla.org ↗
SECURITY POSTURE

Mozilla maintains a high-profile open-source security program with public advisories and bug bounties, but its track record shows a persistent pattern of critical and high-severity memory safety, use-after-free, and sandbox escape vulnerabilities across Firefox and Thunderbird, often requiring urgent patches.

Notable failures
  • CVE-2024-9680: critical RCE via use-after-free in animation timelines
  • CVE-2026-15718: critical invalid pointer in JavaScript WebAssembly exploited in attacks
  • CVE-2026-14241: critical memory safety bugs in Firefox 152.0.3
  • CVE-2026-4688: critical sandbox escape via use-after-free in Disability Access APIs
  • CVE-2026-2768: critical sandbox escape in Storage: IndexedDB
  • CVE-2026-2792: critical memory safety bugs in Firefox ESR 140.7
Patterns: repeated critical use-after-free vulnerabilities across multiple components; frequent memory safety bugs requiring urgent patches; sandbox escape vulnerabilities in diverse subsystems (WebGPU, IndexedDB, WebRender); JIT miscompilation and invalid pointer issues in JavaScript engine
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2024-10-15 CVE-2024-9680 critical Mozilla Firefox contains an actively exploited use-after-free vulnerability in animation timelines that allows remote code execution in the content process.
2022-05-23 CVE-2019-11708 high Mozilla Firefox and Thunderbird suffered a sandbox escape vulnerability allowing remote code execution, which was actively exploited in the wild.
2022-03-07 CVE-2022-26486 high Mozilla Firefox contained an unpatched use-after-free vulnerability in its WebGPU IPC Framework that allowed arbitrary code execution and was actively exploited in the wild.
2022-03-07 CVE-2022-26485 high Firefox use-after-free flaw in XSLT processing allows remote code execution.
2021-11-03 CVE-2020-6820 high Firefox and Thunderbird suffered a use-after-free vulnerability in their ReadableStream handling that was actively exploited in the wild.
2021-11-03 CVE-2020-6819 high Mozilla Firefox and Thunderbird suffered a use-after-free vulnerability that was actively exploited in the wild.
2021-11-03 CVE-2019-17026 high Mozilla Firefox and Thunderbird suffered a type confusion vulnerability in the IonMonkey JIT compiler that was actively exploited in the wild.
2025-10-06 CVE-2010-3765 high Mozilla Firefox, SeaMonkey, and Thunderbird exposed to remote code execution due to unpatched memory corruption issues.
2023-06-22 CVE-2016-9079 high Mozilla Firefox, Firefox ESR, and Thunderbird use-after-free vulnerability exploited in wild
2022-05-25 CVE-2015-4495 high Firefox bypassed Same Origin Policy allowing remote attackers to read arbitrary files or gain privileges.
2022-05-23 CVE-2019-11707 high A type confusion vulnerability in Firefox and Thunderbird's Array.pop function allowed an exploitable crash, listed in CISA's KEV catalog.
2022-03-03 CVE-2013-1675 high A Firefox information disclosure vulnerability allowed remote attackers to read sensitive data from process memory via a crafted website.
2026-06-30 CVE-2026-14241 critical Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
2022-03-28 CVE-2013-1690 high A DoS vulnerability in Firefox and Thunderbird allowed remote attackers to cause denial-of-service or possibly execute malicious code via crafted websites.
2026-08-18 CVE-2026-74936 critical CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was
2026-08-18 CVE-2026-74944 critical CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i
2026-08-18 CVE-2026-74943 critical CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed
2026-08-18 CVE-2026-74940 critical CVE-2026-74940: Use-after-free in the Graphics: Text component. This vulnerability was fixed in
2026-06-16 CVE-2026-12293 critical CVE-2026-12293: Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed i
2026-04-07 CVE-2026-5735 critical CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t
2026-04-07 CVE-2026-5734 critical CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire
2026-03-24 CVE-2026-4691 critical CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability
2026-03-24 CVE-2026-4688 critical CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th
2026-03-24 CVE-2026-4692 critical CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f
2026-03-24 CVE-2026-4698 critical CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w
2026-03-24 CVE-2026-4696 critical CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f
2026-03-24 CVE-2026-4700 critical CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe
2026-03-24 CVE-2026-4689 critical CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC
2026-02-24 CVE-2026-2766 critical CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was f
2026-02-24 CVE-2026-2760 critical CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender c
2026-02-24 CVE-2026-2762 critical CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component. This vulnerabili
2026-02-24 CVE-2026-2763 critical CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed
2026-02-24 CVE-2026-2764 critical CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This
2026-02-24 CVE-2026-2792 critical CVE-2026-2792: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox
2026-02-24 CVE-2026-2793 critical CVE-2026-2793: Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird
2026-02-24 CVE-2026-2795 critical CVE-2026-2795: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
2026-02-24 CVE-2026-2796 critical CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability
2026-02-24 CVE-2026-2797 critical CVE-2026-2797: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
2026-02-24 CVE-2026-2799 critical CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i
2026-02-24 CVE-2026-2807 critical CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bug
2026-02-24 CVE-2026-2778 critical CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML comp
2026-02-24 CVE-2026-2757 critical CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnera
2026-02-24 CVE-2026-2765 critical CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed
2026-02-24 CVE-2026-2772 critical CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fi
2026-02-24 CVE-2026-2771 critical CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fix
2026-02-24 CVE-2026-2770 critical CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was f
2026-02-24 CVE-2026-2767 critical CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was
2026-02-24 CVE-2026-2773 critical CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was
2026-02-24 CVE-2026-2774 critical CVE-2026-2774: Integer overflow in the Audio/Video component. This vulnerability was fixed in F
2026-02-24 CVE-2026-2775 critical CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixe
2026-02-24 CVE-2026-2776 critical CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component i
2026-02-24 CVE-2026-2777 critical CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was f
2026-02-24 CVE-2026-2768 critical CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed
2026-02-24 CVE-2026-2758 critical CVE-2026-2758: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in
2026-02-24 CVE-2026-2759 critical CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerab
2026-02-24 CVE-2026-2761 critical CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixe
2024-10-09 CVE-2024-9680 critical CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit
2023-11-21 CVE-2023-49060 critical CVE-2023-49060: An attacker could have accessed internal pages or data by ex-filtrating a securi
2023-06-19 CVE-2023-29534 critical CVE-2023-29534: Different techniques existed to obscure the fullscreen notification in Firefox a
2022-12-22 CVE-2022-26486 critical CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free
SENTIMENT · TRUSTED SOURCES
synthesisneutral+0.00
No security press or authoritative commentary found in the provided sources; only CVE databases and unrelated news.
synthesisneutral+0.00
Standard CVE disclosure
synthesisneutral+0.00
Standard CVE disclosure
Irrelevant breach tracker site with no coverage of CVE-2020-6819.
Irrelevant CVE database site with no commentary on Mozilla's handling.
Irrelevant breach directory site with no coverage of CVE-2020-6819.
app.opencve.io ↗neutral+0.00
Irrelevant CVE database site with no commentary on Mozilla's handling.
nypost.com ↗neutral+0.00
Irrelevant news article about a child abuse case.
gizmodo.com ↗neutral+0.00
Irrelevant news article about a crypto wallet breach.
cooey ↗neutral+0.00
Neutral CVE disclosure
"Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements."
cooey ↗neutral+0.00
Standard CVE disclosure
"Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts."
cooey ↗neutral+0.00
Neutral CVE database entry with no commentary on Mozilla's handling.
"Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts."
Open questions: Exact employee count for Mozilla Corporation · Specific founding year of Mozilla Corporation vs Mozilla Foundation
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:20:45.165352+00:00