{"id":"SUSE-SU-2026:3658-1","summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following issues:\n\nUpdate to Firefox Extended Support Release 140.14.0 ESR.\n  \n- MFSA 2026-74 (bsc#1274867)\n  - CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component.\n  - CVE-2026-74935: Privilege escalation in the DOM: Networking component.\n  - CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component.\n  - CVE-2026-74937: Use-after-free in the JavaScript: GC component.\n  - CVE-2026-74938: Mitigation bypass in the JavaScript: GC component.\n  - CVE-2026-74939: Privilege escalation in the DOM: Navigation component.\n  - CVE-2026-74940: Use-after-free in the Graphics: Text component.\n  - CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component.\n  - CVE-2026-74942: Privilege escalation in the Remote Settings Client component.\n  - CVE-2026-74943: Use-after-free in the Graphics: ImageLib component.\n  - CVE-2026-74944: Use-after-free in the DOM: Core & HTML component.\n  - CVE-2026-74945: Information disclosure in the Graphics: Text component.\n  - CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n  - CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component.\n  - CVE-2026-74948: Information disclosure in the Graphics component.\n  - CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component.\n  - CVE-2026-74950: Privilege escalation in the Downloads API component.\n  - CVE-2026-74951: Clickjacking issue in Firefox for Android.\n  - CVE-2026-74952: Privilege escalation in the Application Update component.\n  - CVE-2026-74953: Privilege escalation in the Networking: Cookies component.\n  - CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component.\n  - CVE-2026-74955: Privilege escalation in the Request Handling component.\n  - CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component.\n  - CVE-2026-74957: Mitigation bypass in the Safe Browsing component.\n  - CVE-2026-74958: Information disclosure in the WebRTC component.\n  - CVE-2026-74959: Mitigation bypass in the Storage: Cache API component.\n  - CVE-2026-74960: Site isolation issue in the WebExtensions component.\n  - CVE-2026-74961: Side-channel in the Web Audio component.\n  - CVE-2026-74962: Site isolation issue in the Networking: Cookies component.\n  - CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component.\n  - CVE-2026-74964: Integer overflow in the Graphics component.\n  - CVE-2026-74965: Privilege escalation in the Shell Integration component.\n  - CVE-2026-74966: Information disclosure in the Form Autofill component.\n  - CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component.\n  - CVE-2026-74968: Site isolation issue in the Graphics: WebRender component.\n  - CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component.\n  - CVE-2026-74970: Site isolation issue in the Graphics component.\n  - CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component.\n  - CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component.\n  - CVE-2026-74973: Race condition, use-after-free in the Graphics component.\n  - CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component.\n  - CVE-2026-74975: Spoofing issue in the Downloads component in Firefox for Android.\n  - CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component.\n  - CVE-2026-74977: Integer overflow in the Graphics component.\n  - CVE-2026-74978: Clickjacking issue in the Widget component.\n  - CVE-2026-74979: Mitigation bypass in the Add-ons Manager component.\n  - CVE-2026-74980: Clickjacking issue in the Downloads component in Firefox for Android.\n  - CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component.\n  - CVE-2026-74982: Denial-of-service in the Widget component.\n  - CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component.\n  - CVE-2026-74984: Race condition in the JavaScript Engine component.\n  - CVE-2026-74985: Privilege escalation in the Enterprise Policies component.\n  - CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component.\n  - CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154.\n  - CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154.\n  - CVE-2026-74989: Internally found bugs fixed in Firefox 154.\n  - CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and\n    Firefox 154.\n  - CVE-2026-75874: Sandbox escape in the Remote Settings Client component.\n","modified":"2026-08-21T09:15:05.934592615Z","published":"2026-08-20T17:16:18Z","related":["CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74937","CVE-2026-74938","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74947","CVE-2026-74948","CVE-2026-74949","CVE-2026-74950","CVE-2026-74951","CVE-2026-74952","CVE-2026-74953","CVE-2026-74954","CVE-2026-74955","CVE-2026-74956","CVE-2026-74957","CVE-2026-74958","CVE-2026-74959","CVE-2026-74960","CVE-2026-74961","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74966","CVE-2026-74967","CVE-2026-74968","CVE-2026-74969","CVE-2026-74970","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74975","CVE-2026-74976","CVE-2026-74977","CVE-2026-74978","CVE-2026-74979","CVE-2026-74980","CVE-2026-74981","CVE-2026-74982","CVE-2026-74983","CVE-2026-74984","CVE-2026-74985","CVE-2026-74986","CVE-2026-74987","CVE-2026-74988","CVE-2026-74989","CVE-2026-74990","CVE-2026-75874"],"upstream":["CVE-2026-74934","CVE-2026-74935","CVE-2026-74936","CVE-2026-74937","CVE-2026-74938","CVE-2026-74939","CVE-2026-74940","CVE-2026-74941","CVE-2026-74942","CVE-2026-74943","CVE-2026-74944","CVE-2026-74945","CVE-2026-74946","CVE-2026-74947","CVE-2026-74948","CVE-2026-74949","CVE-2026-74950","CVE-2026-74951","CVE-2026-74952","CVE-2026-74953","CVE-2026-74954","CVE-2026-74955","CVE-2026-74956","CVE-2026-74957","CVE-2026-74958","CVE-2026-74959","CVE-2026-74960","CVE-2026-74961","CVE-2026-74962","CVE-2026-74963","CVE-2026-74964","CVE-2026-74965","CVE-2026-74966","CVE-2026-74967","CVE-2026-74968","CVE-2026-74969","CVE-2026-74970","CVE-2026-74971","CVE-2026-74972","CVE-2026-74973","CVE-2026-74974","CVE-2026-74975","CVE-2026-74976","CVE-2026-74977","CVE-2026-74978","CVE-2026-74979","CVE-2026-74980","CVE-2026-74981","CVE-2026-74982","CVE-2026-74983","CVE-2026-74984","CVE-2026-74985","CVE-2026-74986","CVE-2026-74987","CVE-2026-74988","CVE-2026-74989","CVE-2026-74990","CVE-2026-75874"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263658-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74935"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74936"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74937"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74938"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74939"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74940"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74944"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74946"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74948"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74949"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74951"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74957"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74959"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74963"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74964"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74965"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74966"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74968"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74969"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74973"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74975"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74976"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74978"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74979"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74980"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74989"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-74990"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75874"}],"affected":[{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1","MozillaFirefox-translations-other":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"140.14.0-150200.152.251.1","MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"140.14.0-150200.152.251.1","MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"140.14.0-150200.152.251.1","MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-common":"140.14.0-150200.152.251.1","MozillaFirefox-translations-other":"140.14.0-150200.152.251.1","MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-common":"140.14.0-150200.152.251.1","MozillaFirefox-translations-other":"140.14.0-150200.152.251.1","MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1","MozillaFirefox-translations-other":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1","MozillaFirefox-translations-other":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"140.14.0-150200.152.251.1","MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1","MozillaFirefox-translations-other":"140.14.0-150200.152.251.1","MozillaFirefox":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"140.14.0-150200.152.251.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"140.14.0-150200.152.251.1","MozillaFirefox-devel":"140.14.0-150200.152.251.1","MozillaFirefox-translations-common":"140.14.0-150200.152.251.1","MozillaFirefox-translations-other":"140.14.0-150200.152.251.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3658-1.json"}}],"schema_version":"1.9.0"}