Mozilla Firefox patches multiple security flaws
ANSSI advises multiple Firefox vulnerabilities allow security policy bypass and other unspecified issues, fixed in versions 152.0.6 and 152.4 for iOS.
ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in Mozilla Firefox, disclosed via Mozilla security bulletins mfsa2026-66 and mfsa2026-67. The flaws allow an attacker to bypass security policy protections and include an additional issue not further specified by the vendor. Three CVEs are referenced: CVE-2026-14906, CVE-2026-15718, and CVE-2026-15719.
Affected versions are Firefox prior to 152.0.6 and Firefox for iOS prior to 152.4. No evidence of active exploitation is mentioned in the advisory. Users and administrators are advised to apply the vendor-supplied patches referenced in the Mozilla security bulletins to remediate the vulnerabilities.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0887
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free