{"id":"SUSE-SU-2026:23784-1","summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following issues:\n\nFirefox Extended Support Release 153.2.0 ESR MFSA 2026-85 (bsc#1278001):\n\n * CVE-2026-75874 (bmo#2039972)\n Sandbox escape in the Remote Settings Client component\n * CVE-2026-84118 (bmo#2057457)\n Use-after-free in the JavaScript: GC component\n * CVE-2026-84119 (bmo#2057817)\n Sandbox escape due to use-after-free in the DOM: Navigation\n component\n * CVE-2026-84120 (bmo#2058911)\n Use-after-free in the Audio/Video component\n * CVE-2026-84121 (bmo#2059018)\n Sandbox escape due to use-after-free in the DOM: Security\n * CVE-2026-84122 (bmo#2059965)\n * CVE-2026-84123 (bmo#2060047)\n Privilege escalation due to use-after-free in the Graphics:\n WebGPU component\n * CVE-2026-84124 (bmo#2061110)\n Use-after-free in the DOM: Core & HTML component\n * CVE-2026-84125 (bmo#2063871)\n * CVE-2026-74952 (bmo#2021757)\n Privilege escalation in the Application Update component\n * CVE-2026-84129 (bmo#2055028)\n Site isolation issue in the DOM: Navigation component\n * CVE-2026-84130 (bmo#2057834)\n Information disclosure in the Graphics: WebGPU component\n * CVE-2026-84131 (bmo#2060008)\n Privilege escalation due to invalid pointer in the Graphics\n * CVE-2026-84132 (bmo#2063020)\n Information disclosure in the Networking: HTTP component\n * CVE-2026-84133 (bmo#2032388)\n Site isolation issue in the DOM: Push Subscriptions component\n * CVE-2026-84134 (bmo#2044882)\n Other issue in the Profile Backup component\n * CVE-2026-84136 (bmo#2048699)\n Other issue in the DOM: Navigation component\n * CVE-2026-84137 (bmo#2051146)\n Spoofing issue in the DOM: Core & HTML component\n * CVE-2026-84139 (bmo#2060153)\n Clickjacking issue in the DOM: Events component\n * CVE-2026-84140 (bmo#2063780)\n * CVE-2026-84141 (bmo#2063994)\n Integer overflow in the Graphics: ImageLib component\n * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645,\n bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107,\n bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088,\n bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109,\n bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301,\n bmo#2061325)\n Internally found bugs fixed in Firefox 155, Firefox ESR 153.2\n and Firefox ESR 140.15\n * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624,\n bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726,\n bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013,\n bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661,\n bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144,\n bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199,\n bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495,\n bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775,\n bmo#2061799, bmo#2062395, bmo#2062404)\n Internally found bugs fixed in Firefox 155 and Firefox ESR\n 153.2\n * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652,\n bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001,\n bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027,\n bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285,\n bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400,\n bmo#2062419)\n Internally found bugs fixed in Firefox 155, Firefox ESR\n 153.2, Firefox ESR 140.15 and Firefox ESR 115.40\n","modified":"2026-09-27T18:23:12.079813721Z","published":"2026-09-15T14:37:45Z","related":["CVE-2026-74952","CVE-2026-75874","CVE-2026-84118","CVE-2026-84119","CVE-2026-84120","CVE-2026-84121","CVE-2026-84122","CVE-2026-84123","CVE-2026-84124","CVE-2026-84125","CVE-2026-84129","CVE-2026-84130","CVE-2026-84131","CVE-2026-84132","CVE-2026-84133","CVE-2026-84134","CVE-2026-84136","CVE-2026-84137","CVE-2026-84139","CVE-2026-84140","CVE-2026-84141","CVE-2026-84143","CVE-2026-84144","CVE-2026-84145"],"upstream":["CVE-2026-74952","CVE-2026-75874","CVE-2026-84118","CVE-2026-84119","CVE-2026-84120","CVE-2026-84121","CVE-2026-84122","CVE-2026-84123","CVE-2026-84124","CVE-2026-84125","CVE-2026-84129","CVE-2026-84130","CVE-2026-84131","CVE-2026-84132","CVE-2026-84133","CVE-2026-84134","CVE-2026-84136","CVE-2026-84137","CVE-2026-84139","CVE-2026-84140","CVE-2026-84141","CVE-2026-84143","CVE-2026-84144","CVE-2026-84145"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623784-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278001"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75874"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84118"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84120"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84121"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84123"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84124"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84125"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84129"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84130"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84131"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84132"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84133"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84134"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84137"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84139"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84140"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84141"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84143"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84145"}],"affected":[{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.2.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-devel":"153.2.0-160000.1.1","MozillaFirefox-translations-common":"153.2.0-160000.1.1","MozillaFirefox-translations-other":"153.2.0-160000.1.1","MozillaFirefox":"153.2.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23784-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.2.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"153.2.0-160000.1.1","MozillaFirefox":"153.2.0-160000.1.1","MozillaFirefox-devel":"153.2.0-160000.1.1","MozillaFirefox-translations-common":"153.2.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23784-1.json"}}],"schema_version":"1.9.0"}