Memory Corruption Vulnerabilities in Firefox ESR and Firefox
CVE-2026-74988

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74988?

Mozilla's Firefox and Firefox ESR products were found to have multiple internally discovered bugs that could lead to memory corruption. These vulnerabilities, present in versions 153.0, were addressed in subsequent updates, including Firefox version 154 and Firefox ESR 153.1. While exploitation of these defects requires considerable effort, their existence poses a risk to users, warranting immediate attention and update to the latest versions.

Affected Version(s)

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriele Svelto, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
.