Memory Corruption Vulnerability in Firefox and Firefox ESR by Mozilla
CVE-2026-84145

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-84145?

Several internally found bugs in Firefox and its Extended Support Release (ESR) versions revealed potential memory corruption vulnerabilities. These defects, present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14, and Firefox ESR 115.39, indicate that with adequate effort, they might have been exploited by malicious actors. Mozilla has addressed these issues in subsequent releases, including Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2, ensuring enhanced security for users.

Affected Version(s)

Firefox 115.40

Firefox 140.15

Firefox 153.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Leo Tenenbaum, Tom Ritter and the Mozilla Fuzzing Team
.