{"id":"SUSE-SU-2026:4264-1","summary":"Security update for MozillaFirefox","details":"This update for MozillaFirefox fixes the following issues:\n\nUpdate to Firefox Extended Support Release 153.3.0 ESRi (MFSA 2026-93, bsc#1280371)\n \n- CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component.\n- CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n- CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n- CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n- CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n- CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n- CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n- CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n- CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.\n- CVE-2026-92015: Privilege escalation in the WebExtensions component.\n- CVE-2026-92016: Use-after-free in the Disability Access APIs component.\n- CVE-2026-92017: Privilege escalation in the DOM: Service Workers component.\n- CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component.\n- CVE-2026-92019: Mitigation bypass in the Remote Settings Client component.\n- CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component.\n- CVE-2026-92022: Use-after-free in the DOM: HTML Parser component.\n- CVE-2026-92023: Use-after-free in the XML component.\n- CVE-2026-92024: Use-after-free in the SVG component.\n- CVE-2026-92025: Use-after-free in the DOM: Navigation component.\n- CVE-2026-92026: Use-after-free in the Networking component.\n- CVE-2026-92027: Use-after-free in the DOM: Streams component.\n- CVE-2026-92028: Use-after-free in the DOM: Core & HTML component.\n- CVE-2026-92029: Use-after-free in the SVG component.\n- CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component.\n- CVE-2026-92031: Information disclosure in the Graphics: ImageLib component.\n- CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component.\n- CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component.\n- CVE-2026-92038: Mitigation bypass in the Remote Settings Client component.\n- CVE-2026-92039: Mitigation bypass in the DOM: Notifications component.\n- CVE-2026-92041: Mitigation bypass in the DOM: Networking component.\n- CVE-2026-92042: Race condition in the DOM: Content Processes component.\n- CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component.\n- CVE-2026-92044: Information disclosure in the Networking: HTTP component.\n- CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component.\n- CVE-2026-92046: Use-after-free in the Graphics component.\n- CVE-2026-92047: Privilege escalation in the Crash Reporting component.\n- CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.\n- CVE-2026-92049: Use-after-free in the Widget: Win32 component.\n- CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component.\n- CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component.\n- CVE-2026-92054: Privilege escalation in the Memory component.\n- CVE-2026-92055: Privilege escalation in the DevTools component.\n- CVE-2026-92056: Use-after-free in the Graphics: Text component.\n- CVE-2026-92057: Mitigation bypass in the Enterprise Policies component.\n- CVE-2026-92058: Use-after-free in the Graphics component.\n- CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component.\n- CVE-2026-92060: Use-after-free in the Internationalization component.\n- CVE-2026-92062: Privilege escalation in the Session Restore component.\n- CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.\n- CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.\n- CVE-2026-92067: Use-after-free in the Widget: Gtk component.\n- CVE-2026-92068: Site isolation issue in the Reader Mode component.\n- CVE-2026-92069: Spoofing issue in the DOM: Navigation component.\n- CVE-2026-92070: Information disclosure in the Networking component.\n- CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.\n- CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component.\n- CVE-2026-92073: Privilege escalation in the Enterprise Policies component.\n- CVE-2026-92074: Mitigation bypass in the Popup Blocker component.\n- CVE-2026-92075: Mitigation bypass in the Networking component.\n- CVE-2026-92076: Incorrect boundary conditions in the Networking component.\n- CVE-2026-92077: Denial-of-service in the SVG component.\n- CVE-2026-92078: Denial-of-service in the Security component.\n- CVE-2026-92079: Mitigation bypass in the Widget: Win32 component.\n","modified":"2026-09-19T09:00:03.896776074Z","published":"2026-09-18T13:54:57Z","related":["CVE-2026-92005","CVE-2026-92006","CVE-2026-92007","CVE-2026-92008","CVE-2026-92009","CVE-2026-92010","CVE-2026-92011","CVE-2026-92012","CVE-2026-92013","CVE-2026-92015","CVE-2026-92016","CVE-2026-92017","CVE-2026-92018","CVE-2026-92019","CVE-2026-92020","CVE-2026-92022","CVE-2026-92023","CVE-2026-92024","CVE-2026-92025","CVE-2026-92026","CVE-2026-92027","CVE-2026-92028","CVE-2026-92029","CVE-2026-92030","CVE-2026-92031","CVE-2026-92032","CVE-2026-92035","CVE-2026-92038","CVE-2026-92039","CVE-2026-92041","CVE-2026-92042","CVE-2026-92043","CVE-2026-92044","CVE-2026-92045","CVE-2026-92046","CVE-2026-92047","CVE-2026-92048","CVE-2026-92049","CVE-2026-92052","CVE-2026-92053","CVE-2026-92054","CVE-2026-92055","CVE-2026-92056","CVE-2026-92057","CVE-2026-92058","CVE-2026-92059","CVE-2026-92060","CVE-2026-92062","CVE-2026-92064","CVE-2026-92065","CVE-2026-92067","CVE-2026-92068","CVE-2026-92069","CVE-2026-92070","CVE-2026-92071","CVE-2026-92072","CVE-2026-92073","CVE-2026-92074","CVE-2026-92075","CVE-2026-92076","CVE-2026-92077","CVE-2026-92078","CVE-2026-92079"],"upstream":["CVE-2026-92005","CVE-2026-92006","CVE-2026-92007","CVE-2026-92008","CVE-2026-92009","CVE-2026-92010","CVE-2026-92011","CVE-2026-92012","CVE-2026-92013","CVE-2026-92015","CVE-2026-92016","CVE-2026-92017","CVE-2026-92018","CVE-2026-92019","CVE-2026-92020","CVE-2026-92022","CVE-2026-92023","CVE-2026-92024","CVE-2026-92025","CVE-2026-92026","CVE-2026-92027","CVE-2026-92028","CVE-2026-92029","CVE-2026-92030","CVE-2026-92031","CVE-2026-92032","CVE-2026-92035","CVE-2026-92038","CVE-2026-92039","CVE-2026-92041","CVE-2026-92042","CVE-2026-92043","CVE-2026-92044","CVE-2026-92045","CVE-2026-92046","CVE-2026-92047","CVE-2026-92048","CVE-2026-92049","CVE-2026-92052","CVE-2026-92053","CVE-2026-92054","CVE-2026-92055","CVE-2026-92056","CVE-2026-92057","CVE-2026-92058","CVE-2026-92059","CVE-2026-92060","CVE-2026-92062","CVE-2026-92064","CVE-2026-92065","CVE-2026-92067","CVE-2026-92068","CVE-2026-92069","CVE-2026-92070","CVE-2026-92071","CVE-2026-92072","CVE-2026-92073","CVE-2026-92074","CVE-2026-92075","CVE-2026-92076","CVE-2026-92077","CVE-2026-92078","CVE-2026-92079"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264264-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280371"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92005"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92006"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92008"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92009"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92012"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92017"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92018"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92022"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92024"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92025"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92026"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92027"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92028"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92029"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92030"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92035"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92038"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92039"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92044"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92047"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92054"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92056"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92057"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92058"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92060"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92062"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92064"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92065"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92067"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92068"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92069"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92070"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92071"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92072"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92073"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92074"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92075"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92076"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92077"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92078"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-92079"}],"affected":[{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"153.3.0-150400.157.8.1","MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-common":"153.3.0-150400.157.8.1","MozillaFirefox-translations-other":"153.3.0-150400.157.8.1","MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1","MozillaFirefox-translations-other":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"153.3.0-150400.157.8.1","MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-common":"153.3.0-150400.157.8.1","MozillaFirefox-translations-other":"153.3.0-150400.157.8.1","MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1","MozillaFirefox-translations-other":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1","MozillaFirefox-translations-other":"153.3.0-150400.157.8.1","MozillaFirefox":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1","MozillaFirefox-translations-other":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-translations-other":"153.3.0-150400.157.8.1","MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox":"153.3.0-150400.157.8.1","MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1","MozillaFirefox-translations-other":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}},{"package":{"name":"MozillaFirefox","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"153.3.0-150400.157.8.1"}]}],"ecosystem_specific":{"binaries":[{"MozillaFirefox-devel":"153.3.0-150400.157.8.1","MozillaFirefox-translations-common":"153.3.0-150400.157.8.1","MozillaFirefox-translations-other":"153.3.0-150400.157.8.1","MozillaFirefox":"153.3.0-150400.157.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4264-1.json"}}],"schema_version":"1.9.0"}