# Mozilla patches 40+ flaws in Firefox 151

Published: 2026-05-20 · Severity: medium
Canonical: https://vorant.io/reports/78d86372-22dd-52b8-a1b0-55b7ce55c2a5/mozilla-patches-40-flaws-in-firefox-151

> Mozilla released updates for Firefox, Firefox ESR, and Firefox for iOS addressing over 40 vulnerabilities, including critical memory safety bugs and sandbox escapes that could enable arbitrary code execution.

Mozilla has released security updates for multiple products addressing over 40 vulnerabilities across Firefox 151, Firefox ESR 140.11, Firefox ESR 115.36, and Firefox for iOS 151.0. The most severe vulnerabilities include memory safety bugs (CVE-2026-8973, CVE-2026-8974, CVE-2026-8975), multiple sandbox escape issues in various components, and use-after-free conditions in the DOM. These critical flaws could allow attackers to execute arbitrary code on affected systems.

The vulnerabilities span multiple attack vectors, including incorrect boundary conditions in Audio/Video and JavaScript Engine components, same-origin policy bypasses, and privilege escalation issues in DOM, WebRTC, and Enterprise Policies components. Several information disclosure vulnerabilities affect the Graphics, IP Protection, and Security components. Additional lower-severity issues include spoofing vulnerabilities in the Toolbar, Form Autofill, and Popup Blocker components, as well as integer overflow conditions in Widget and Networking components.

MS-ISAC reports no active exploitation of these vulnerabilities in the wild. Organizations are advised to apply the updates immediately after appropriate testing. The impact of successful exploitation depends on user privileges, with administrative accounts facing greater risk than standard users. Mozilla recommends implementing defense-in-depth measures including application allowlisting, exploit protection features, DNS filtering, and user security awareness training.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8388, CVE-2026-8391, CVE-2026-8401, CVE-2026-8706, CVE-2026-8945, CVE-2026-8946, CVE-2026-8947, CVE-2026-8948, CVE-2026-8949, CVE-2026-8950, CVE-2026-8951, CVE-2026-8952, CVE-2026-8953, CVE-2026-8954, CVE-2026-8955, CVE-2026-8956, CVE-2026-8957, CVE-2026-8958, CVE-2026-8959, CVE-2026-8960, CVE-2026-8961, CVE-2026-8962, CVE-2026-8963, CVE-2026-8964, CVE-2026-8965, CVE-2026-8966, CVE-2026-8967, CVE-2026-8968, CVE-2026-8969, CVE-2026-8970, CVE-2026-8971, CVE-2026-8972, CVE-2026-8973, CVE-2026-8974, CVE-2026-8975

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-052

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/78d86372-22dd-52b8-a1b0-55b7ce55c2a5/mozilla-patches-40-flaws-in-firefox-151.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
