Description
Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability consists of multiple internally found bugs in Firefox 154 and Firefox ESR 153.1 that caused memory corruption or other security-relevant defects. The memory errors could be exploited with sufficient effort, potentially allowing an attacker to execute arbitrary code within the browser’s context, leading to a compromise of confidentiality, integrity, and availability of the affected system.

Affected Systems

Firefox 154 and Firefox ESR 153.1 are affected. The bugs are fixed in Firefox 155 and Firefox ESR 153.2, so systems running those earlier releases are susceptible.

Risk and Exploitability

No CVSS score is publicly available, and the EPSS score is not reported, indicating no current data on exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on typical exploitation pathways for memory corruption in web browsers, the likely attack vector is through a malicious web page or extension loaded in the affected Firefox versions. An attacker would need to craft content that triggers the underlying memory error; no public exploitation has been documented yet, but the potential for abuse remains.

Generated by OpenCVE AI on September 1, 2026 at 14:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 155 or Firefox ESR 153.2 or later
  • Enable automatic updates in Firefox to receive future security patches promptly
  • Review installed extensions and remove any that are no longer needed or come from untrusted sources

Generated by OpenCVE AI on September 1, 2026 at 14:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-416

Tue, 01 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Internally found bugs present in Firefox 154 and Firefox ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:19:11.104Z

Reserved: 2026-09-01T07:26:01.858Z

Link: CVE-2026-84144

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:08.563

Modified: 2026-09-01T13:20:08.563

Link: CVE-2026-84144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:30:18Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free