GBHackers

Mozilla Firefox 150 Released With Fixes for Multiple Code Execution Vulnerabilities


Mozilla has released Firefox 150 to patch 41 security vulnerabilities, including multiple high-severity flaws that could lead to remote code execution.

Users should immediately update their browsers to protect against these critical memory corruption and use-after-free bugs.

Critical Vulnerability Details

The most dangerous flaws include use-after-free vulnerabilities in the DOM (CVE-2026-6746) and WebRTC (CVE-2026-6747) components.

These occur when the application incorrectly uses a freed memory pointer, potentially allowing attackers to execute arbitrary malicious code or crash the system.

Security researchers notably utilized Anthropic’s Claude AI to help discover several of these complex memory safety bugs.

This update resolves a wide spectrum of issues ranging from high-severity memory corruption bugs to low-impact denial-of-service vulnerabilities.

The comprehensive breakdown of all Common Vulnerabilities and Exposures (CVEs) addressed in Firefox 150 is detailed below.

CVE IDVulnerability DescriptionImpact
CVE-2026-6746Use-after-free in the DOM: Core & HTML componentHigh 
CVE-2026-6747Use-after-free in the WebRTC componentHigh 
CVE-2026-6748Uninitialized memory in the Audio/Video: Web Codecs componentHigh 
CVE-2026-6749Information disclosure due to uninitialized memory in Graphics: Canvas2DHigh 
CVE-2026-6750Privilege escalation in the Graphics: WebRender componentHigh 
CVE-2026-6751Uninitialized memory in the Audio/Video: Web Codecs componentHigh 
CVE-2026-6752Incorrect boundary conditions in the WebRTC componentHigh 
CVE-2026-6753Incorrect boundary conditions in the WebRTC componentHigh 
CVE-2026-6754Use-after-free in the JavaScript Engine componentHigh 
CVE-2026-6755Mitigation bypass in the DOM: postMessage componentModerate 
CVE-2026-6756Mitigation bypass in Firefox for AndroidModerate 
CVE-2026-6757Invalid pointer in the JavaScript: WebAssembly componentModerate 
CVE-2026-6758Use-after-free in the JavaScript: WebAssembly componentModerate 
CVE-2026-6759Use-after-free in the Widget: Cocoa componentModerate 
CVE-2026-6760Mitigation bypass in the Networking: Cookies componentModerate 
CVE-2026-6761Privilege escalation in the Networking componentModerate 
CVE-2026-6762Spoofing issue in the DOM: Core & HTML componentModerate 
CVE-2026-6763Mitigation bypass in the File Handling componentModerate 
CVE-2026-6764Incorrect boundary conditions in the DOM: Device Interfaces componentModerate 
CVE-2026-6765Information disclosure in the Form Autofill componentModerate 
CVE-2026-6766Incorrect boundary conditions in the Libraries component in NSSModerate 
CVE-2026-6767Other issue in the Libraries component in NSSModerate 
CVE-2026-6768Mitigation bypass in the Networking: Cookies componentModerate 
CVE-2026-6769Privilege escalation in the Debugger componentModerate 
CVE-2026-6770Other issue in the Storage: IndexedDB componentModerate 
CVE-2026-6771Mitigation bypass in the DOM: Security componentModerate 
CVE-2026-6772Incorrect boundary conditions in the Libraries component in NSSModerate 
CVE-2026-6773Denial-of-service due to integer overflow in Graphics: WebGPULow 
CVE-2026-6774Mitigation bypass in the DOM: Security componentLow 
CVE-2026-6775Incorrect boundary conditions in the WebRTC componentLow 
CVE-2026-6776Incorrect boundary conditions in the WebRTC: Networking componentLow 
CVE-2026-6777Other issue in the Networking: DNS componentLow 
CVE-2026-6778Invalid pointer in the Audio/Video: Playback componentLow 
CVE-2026-6779Other issue in the JavaScript Engine componentLow 
CVE-2026-6780Denial-of-service in the Audio/Video: Playback componentLow 
CVE-2026-6781Denial-of-service in the Audio/Video: Playback componentLow 
CVE-2026-6782Information disclosure in the IP Protection componentLow 
CVE-2026-6783Incorrect boundary conditions/integer overflow in Audio/Video: PlaybackLow 
CVE-2026-6784Memory safety bugs fixed in Firefox 150 and Thunderbird 150High 
CVE-2026-6785Memory safety bugs fixed in ESR 115.35, ESR 140.10, and Firefox 150High 
CVE-2026-6786Memory safety bugs fixed in ESR 140.10 and Firefox 150High 

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.



Source link