Firefox 153: Mozilla Fixes 25 Coordinated Vulnerabilities in Single July 22 Disclosure
Key findings • Mozilla patched 25 coordinated vulnerabilities in Firefox 153 released on July 22, 2026. • Vulnerabilities include memory safety bugs, privilege escalations, and mitigation byp…
Key findings
- Mozilla patched 25 coordinated vulnerabilities in Firefox 153 released on July 22, 2026.
- Vulnerabilities include memory safety bugs, privilege escalations, and mitigation bypasses across multiple components.
- Specific issues affect Firefox for Android, including spoofing and clickjacking.
- The batch includes several graphics-related vulnerabilities, such as WebGPU and ImageLib component flaws.
- All disclosed vulnerabilities were fixed in Firefox version 153.
On July 22, 2026, Mozilla Corporation released Firefox 153, addressing a significant batch of 25 vulnerabilities that were disclosed together. These vulnerabilities span various components of the browser, including the DOM, Graphics, Networking, and JavaScript engine, with potential impacts ranging from information disclosure and mitigation bypasses to privilege escalation and even arbitrary code execution. The swift patching in a single release highlights Mozilla's commitment to user security.
Several vulnerabilities fall into the category of memory safety bugs. CVE-2026-16411 specifically mentions memory corruption issues in Firefox 152, with the potential for arbitrary code execution if exploited. Similarly, CVE-2026-16386 and CVE-2026-16384 point to information disclosures due to uninitialized memory in the Graphics: WebGPU component.
Other notable issues include mitigation bypasses in the DOM: Security component (CVE-2026-16394), Networking component (CVE-2026-16406 and CVE-2026-16370), and DOM: Service Workers component (CVE-2026-16407). Privilege escalation vulnerabilities were also identified in the DOM: Content Processes component (CVE-2026-16372) and the DOM: Navigation component (CVE-2026-16366).
The batch also includes several issues related to the Graphics component, such as a site isolation issue (CVE-2026-16398), a denial-of-service vulnerability in the Graphics: WebGPU component (CVE-2026-16376), an integer overflow in the Graphics: ImageLib component (CVE-2026-16402), and incorrect boundary conditions in the Graphics: WebGPU component (CVE-2026-16393).
For Firefox for Android users, specific vulnerabilities include a spoofing issue in the Address Bar (CVE-2026-16403), a clickjacking issue in the WebExtensions component (CVE-2026-16397), and an information disclosure in the Privacy component (CVE-2026-16373).
The coordinated disclosure of these 25 vulnerabilities and their subsequent patching in Firefox 153 underscore the importance of timely updates for users to protect themselves against potential exploits. Users are strongly advised to ensure they are running the latest version of Firefox to benefit from these security enhancements.