FAIL › dossier
mozilla
VENDOR· dossier confidence 40%
Mozilla is a nonprofit-backed vendor of the Firefox browser and Thunderbird email client with a strong open-source security program, but its internal failure history reveals a chronic pattern of critical memory safety, use-after-free, and sandbox escape vulnerabilities that require urgent patches and expose users to remote code execution and privilege escalation.
PROFILE
Categorysoftware vendorWhat they doMozilla develops the Firefox web browser, Thunderbird email client, and related open-source software, operating as a nonprofit-backed technology organization focused on internet privacy and user choice.Ownershipnonprofit-backed
Websitehttps://www.mozilla.org ↗
SECURITY POSTURE
Mozilla maintains a high-profile open-source security program with public advisories and bug bounties, but its track record shows a persistent pattern of critical and high-severity memory safety, use-after-free, and sandbox escape vulnerabilities across Firefox and Thunderbird, often requiring urgent patches.
Notable failures
- CVE-2024-9680: critical RCE via use-after-free in animation timelines
- CVE-2026-15718: critical invalid pointer in JavaScript WebAssembly exploited in attacks
- CVE-2026-14241: critical memory safety bugs in Firefox 152.0.3
- CVE-2026-4688: critical sandbox escape via use-after-free in Disability Access APIs
- CVE-2026-2768: critical sandbox escape in Storage: IndexedDB
- CVE-2026-2792: critical memory safety bugs in Firefox ESR 140.7
Patterns: repeated critical use-after-free vulnerabilities across multiple components; frequent memory safety bugs requiring urgent patches; sandbox escape vulnerabilities in diverse subsystems (WebGPU, IndexedDB, WebRender); JIT miscompilation and invalid pointer issues in JavaScript engine
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-10-15 | CVE-2024-9680 | critical | Mozilla Firefox contains an actively exploited use-after-free vulnerability in animation timelines that allows remote code execution in the content process. |
| 2022-05-23 | CVE-2019-11708 | high | Mozilla Firefox and Thunderbird suffered a sandbox escape vulnerability allowing remote code execution, which was actively exploited in the wild. |
| 2022-03-07 | CVE-2022-26486 | high | Mozilla Firefox contained an unpatched use-after-free vulnerability in its WebGPU IPC Framework that allowed arbitrary code execution and was actively exploited in the wild. |
| 2022-03-07 | CVE-2022-26485 | high | Firefox use-after-free flaw in XSLT processing allows remote code execution. |
| 2021-11-03 | CVE-2020-6820 | high | Firefox and Thunderbird suffered a use-after-free vulnerability in their ReadableStream handling that was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-6819 | high | Mozilla Firefox and Thunderbird suffered a use-after-free vulnerability that was actively exploited in the wild. |
| 2021-11-03 | CVE-2019-17026 | high | Mozilla Firefox and Thunderbird suffered a type confusion vulnerability in the IonMonkey JIT compiler that was actively exploited in the wild. |
| 2025-10-06 | CVE-2010-3765 | high | Mozilla Firefox, SeaMonkey, and Thunderbird exposed to remote code execution due to unpatched memory corruption issues. |
| 2023-06-22 | CVE-2016-9079 | high | Mozilla Firefox, Firefox ESR, and Thunderbird use-after-free vulnerability exploited in wild |
| 2022-05-25 | CVE-2015-4495 | high | Firefox bypassed Same Origin Policy allowing remote attackers to read arbitrary files or gain privileges. |
| 2022-05-23 | CVE-2019-11707 | high | A type confusion vulnerability in Firefox and Thunderbird's Array.pop function allowed an exploitable crash, listed in CISA's KEV catalog. |
| 2022-03-03 | CVE-2013-1675 | high | A Firefox information disclosure vulnerability allowed remote attackers to read sensitive data from process memory via a crafted website. |
| 2026-06-30 | CVE-2026-14241 | critical | Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4. |
| 2022-03-28 | CVE-2013-1690 | high | A DoS vulnerability in Firefox and Thunderbird allowed remote attackers to cause denial-of-service or possibly execute malicious code via crafted websites. |
| 2026-08-18 | CVE-2026-74936 | critical | CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was |
| 2026-08-18 | CVE-2026-74944 | critical | CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i |
| 2026-08-18 | CVE-2026-74943 | critical | CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed |
| 2026-08-18 | CVE-2026-74940 | critical | CVE-2026-74940: Use-after-free in the Graphics: Text component. This vulnerability was fixed in |
| 2026-06-16 | CVE-2026-12293 | critical | CVE-2026-12293: Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed i |
| 2026-04-07 | CVE-2026-5735 | critical | CVE-2026-5735: Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of t |
| 2026-04-07 | CVE-2026-5734 | critical | CVE-2026-5734: Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Fire |
| 2026-03-24 | CVE-2026-4691 | critical | CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component. This vulnerability |
| 2026-03-24 | CVE-2026-4688 | critical | CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component. Th |
| 2026-03-24 | CVE-2026-4692 | critical | CVE-2026-4692: Sandbox escape in the Responsive Design Mode component. This vulnerability was f |
| 2026-03-24 | CVE-2026-4698 | critical | CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w |
| 2026-03-24 | CVE-2026-4696 | critical | CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component. This vulnerability was f |
| 2026-03-24 | CVE-2026-4700 | critical | CVE-2026-4700: Mitigation bypass in the Networking: HTTP component. This vulnerability was fixe |
| 2026-03-24 | CVE-2026-4689 | critical | CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC |
| 2026-02-24 | CVE-2026-2766 | critical | CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2760 | critical | CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender c |
| 2026-02-24 | CVE-2026-2762 | critical | CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component. This vulnerabili |
| 2026-02-24 | CVE-2026-2763 | critical | CVE-2026-2763: Use-after-free in the JavaScript Engine component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2764 | critical | CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component. This |
| 2026-02-24 | CVE-2026-2792 | critical | CVE-2026-2792: Memory safety bugs present in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox |
| 2026-02-24 | CVE-2026-2793 | critical | CVE-2026-2793: Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird |
| 2026-02-24 | CVE-2026-2795 | critical | CVE-2026-2795: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2796 | critical | CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability |
| 2026-02-24 | CVE-2026-2797 | critical | CVE-2026-2797: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2799 | critical | CVE-2026-2799: Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i |
| 2026-02-24 | CVE-2026-2807 | critical | CVE-2026-2807: Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bug |
| 2026-02-24 | CVE-2026-2778 | critical | CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML comp |
| 2026-02-24 | CVE-2026-2757 | critical | CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnera |
| 2026-02-24 | CVE-2026-2765 | critical | CVE-2026-2765: Use-after-free in the JavaScript Engine component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2772 | critical | CVE-2026-2772: Use-after-free in the Audio/Video: Playback component. This vulnerability was fi |
| 2026-02-24 | CVE-2026-2771 | critical | CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component. This vulnerability was fix |
| 2026-02-24 | CVE-2026-2770 | critical | CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2767 | critical | CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was |
| 2026-02-24 | CVE-2026-2773 | critical | CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was |
| 2026-02-24 | CVE-2026-2774 | critical | CVE-2026-2774: Integer overflow in the Audio/Video component. This vulnerability was fixed in F |
| 2026-02-24 | CVE-2026-2775 | critical | CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixe |
| 2026-02-24 | CVE-2026-2776 | critical | CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component i |
| 2026-02-24 | CVE-2026-2777 | critical | CVE-2026-2777: Privilege escalation in the Messaging System component. This vulnerability was f |
| 2026-02-24 | CVE-2026-2768 | critical | CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed |
| 2026-02-24 | CVE-2026-2758 | critical | CVE-2026-2758: Use-after-free in the JavaScript: GC component. This vulnerability was fixed in |
| 2026-02-24 | CVE-2026-2759 | critical | CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerab |
| 2026-02-24 | CVE-2026-2761 | critical | CVE-2026-2761: Sandbox escape in the Graphics: WebRender component. This vulnerability was fixe |
| 2024-10-09 | CVE-2024-9680 | critical | CVE-2024-9680: An attacker was able to achieve code execution in the content process by exploit |
| 2023-11-21 | CVE-2023-49060 | critical | CVE-2023-49060: An attacker could have accessed internal pages or data by ex-filtrating a securi |
| 2023-06-19 | CVE-2023-29534 | critical | CVE-2023-29534: Different techniques existed to obscure the fullscreen notification in Firefox a |
| 2022-12-22 | CVE-2022-26486 | critical | CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free |
SENTIMENT · TRUSTED SOURCES
synthesisneutral+0.00
No security press or authoritative commentary found in the provided sources; only CVE databases and unrelated news.
synthesisneutral+0.00
Standard CVE disclosure
synthesisneutral+0.00
Standard CVE disclosure
Irrelevant breach tracker site with no coverage of CVE-2020-6819.
Irrelevant CVE database site with no commentary on Mozilla's handling.
Irrelevant breach directory site with no coverage of CVE-2020-6819.
Irrelevant CVE database site with no commentary on Mozilla's handling.
Irrelevant news article about a child abuse case.
Irrelevant news article about a crypto wallet breach.
Neutral CVE disclosure
"Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements."
Standard CVE disclosure
"Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts."
Neutral CVE database entry with no commentary on Mozilla's handling.
"Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts."
DOSSIER SOURCES
- Firefox - Wikipedia · en.wikipedia.org
- Mozilla Stock | Valuation, Funding, Investors | Notice.co · notice.co
- DuckDuckGo - Wikipedia · en.wikipedia.org
- Mozilla Firefox Security Vulnerabilities in 2026 · stack.watch
- Mozilla Firefox Zero-day Vulnerabilities Exploited in Attacks (CVE-2026 ... · threatprotect.qualys.com
- Security Vulnerabilities fixed in Firefox 152.0.6 — Mozilla · www.mozilla.org
- Alphabet Inc. (GOOGL) Employee Count | Workforce Growth & Hiring Trends ... · stocknear.com
- Mozilla Salaries | Levels.fyi · www.levels.fyi
- Mozilla Stock | Valuation, Funding, Investors | Notice.co · notice.co
Open questions: Exact employee count for Mozilla Corporation · Specific founding year of Mozilla Corporation vs Mozilla Foundation
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:20:45.165352+00:00