critical Security update for mozillafirefox
SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3221


This update for MozillaFirefox fixes the following issue: - Firefox Extended Support Release 140.13.0 ESR (MFSA 2026-70, bsc#1271649): - CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component. - CVE-2026-15719: Site isolation issue in the DOM: Navigation component. - CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component. - CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component. - CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component. - CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component. - CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component. - CVE-2026-16354: Information disclosure in the Graphics: ImageLib component. - CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component. - CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component. - CVE-2026-16357: Incorrect boundary conditions in the Graphics component. - CVE-2026-16358: Site isolation issue in the Graphics: WebRender component. - CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component. - CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153. - CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13. - CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component. - CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component. - CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component. - CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component. - CVE-2026-16371: Privilege escalation in the DOM: Navigation component. - CVE-2026-16374: Information disclosure in the Framework component in DevTools. - CVE-2026-16375: Site isolation issue in the Networking: HTTP component. - CVE-2026-16377: Mitigation bypass in the PDF Viewer component. - CVE-2026-16379: Privilege escalation in the DOM: Content Processes component. - CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component. - CVE-2026-16383: Mitigation bypass in the DOM: Networking component. - CVE-2026-16387: Site isolation issue in the Networking component. - CVE-2026-16390: Mitigation bypass in the Enterprise Policies component. - CVE-2026-16391: Information disclosure in the Storage: IndexedDB component. - CVE-2026-16396: Privilege escalation in WebExtensions. - CVE-2026-16405: Information disclosure in the Networking: WebSockets component. - CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153.


cloud_download Downloads

Desktop Applications Module 15.7 ppc64le
Desktop Applications Module 15.7 s390x
Desktop Applications Module 15.7 x86_64
Desktop Applications Module 15.7 aarch64