You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Changelog: drop the per-CVE listing from the 153.1.0 entry
Fifty-two CVEs broken out by severity, one linked bullet each, ran to sixty
lines and buried the rest of the entry. The summary paragraph keeps the count,
the severity breakdown and the link to MFSA 2026-77, which is a better place to
read the full list than a copy of it here.
Only the 153.1.0 entry changes. Older entries keep their listings: that is what
those releases actually published, and rewriting them would misrepresent them.
releases going forward no longer generate the listing at all.
The published GitHub release body for 153.1.0 was edited to match.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: Docs/Changelog.md
-61Lines changed: 0 additions & 61 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,67 +22,6 @@ All releases of ducksteps. Newest first.
22
22
23
23
🛡️ Addressed 52 CVEs from [Mozilla Foundation Security Advisory 2026-77](https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/) (August 18, 2026). This one's mostly patching holes; 19 high, 23 moderate, and 10 low severity CVEs squashed, nothing screaming louder than the rest but the high count alone is enough to not sit on this. Update when you get a sec.
24
24
25
-
High severity:
26
-
27
-
-**[CVE-2026-74934](https://www.cve.org/CVERecord?id=CVE-2026-74934)** Site isolation issue in the Graphics: CanvasWebGL component
28
-
-**[CVE-2026-74935](https://www.cve.org/CVERecord?id=CVE-2026-74935)** Privilege escalation in the DOM: Networking component
29
-
-**[CVE-2026-74936](https://www.cve.org/CVERecord?id=CVE-2026-74936)** Use-after-free in the JavaScript: WebAssembly component
30
-
-**[CVE-2026-74937](https://www.cve.org/CVERecord?id=CVE-2026-74937)** Use-after-free in the JavaScript: GC component
31
-
-**[CVE-2026-74938](https://www.cve.org/CVERecord?id=CVE-2026-74938)** Mitigation bypass in the JavaScript: GC component
32
-
-**[CVE-2026-74939](https://www.cve.org/CVERecord?id=CVE-2026-74939)** Privilege escalation in the DOM: Navigation component
33
-
-**[CVE-2026-74940](https://www.cve.org/CVERecord?id=CVE-2026-74940)** Use-after-free in the Graphics: Text component
34
-
-**[CVE-2026-74941](https://www.cve.org/CVERecord?id=CVE-2026-74941)** Privilege escalation in the Graphics: CanvasWebGL component
35
-
-**[CVE-2026-74942](https://www.cve.org/CVERecord?id=CVE-2026-74942)** Privilege escalation in the Remote Settings Client component
36
-
-**[CVE-2026-74943](https://www.cve.org/CVERecord?id=CVE-2026-74943)** Use-after-free in the Graphics: ImageLib component
37
-
-**[CVE-2026-74944](https://www.cve.org/CVERecord?id=CVE-2026-74944)** Use-after-free in the DOM: Core & HTML component
38
-
-**[CVE-2026-74945](https://www.cve.org/CVERecord?id=CVE-2026-74945)** Information disclosure in the Graphics: Text component
39
-
-**[CVE-2026-74946](https://www.cve.org/CVERecord?id=CVE-2026-74946)** Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
40
-
-**[CVE-2026-74947](https://www.cve.org/CVERecord?id=CVE-2026-74947)** Privilege escalation due to invalid pointer in the Graphics component
41
-
-**[CVE-2026-74948](https://www.cve.org/CVERecord?id=CVE-2026-74948)** Information disclosure in the Graphics component
42
-
-**[CVE-2026-74949](https://www.cve.org/CVERecord?id=CVE-2026-74949)** Privilege escalation due to use-after-free in the Graphics: Canvas2D component
43
-
-**[CVE-2026-74987](https://www.cve.org/CVERecord?id=CVE-2026-74987)** Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
44
-
-**[CVE-2026-74988](https://www.cve.org/CVERecord?id=CVE-2026-74988)** Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154
45
-
-**[CVE-2026-74990](https://www.cve.org/CVERecord?id=CVE-2026-74990)** Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
46
-
47
-
Moderate severity:
48
-
49
-
-**[CVE-2026-74950](https://www.cve.org/CVERecord?id=CVE-2026-74950)** Privilege escalation in the Downloads API component
50
-
-**[CVE-2026-74953](https://www.cve.org/CVERecord?id=CVE-2026-74953)** Privilege escalation in the Networking: Cookies component
51
-
-**[CVE-2026-74954](https://www.cve.org/CVERecord?id=CVE-2026-74954)** Information disclosure due to side-channel in the Storage: Cache API component
52
-
-**[CVE-2026-74955](https://www.cve.org/CVERecord?id=CVE-2026-74955)** Privilege escalation in the Request Handling component
53
-
-**[CVE-2026-74956](https://www.cve.org/CVERecord?id=CVE-2026-74956)** Same-origin policy bypass in the DOM: Service Workers component
54
-
-**[CVE-2026-74957](https://www.cve.org/CVERecord?id=CVE-2026-74957)** Mitigation bypass in the Safe Browsing component
55
-
-**[CVE-2026-74958](https://www.cve.org/CVERecord?id=CVE-2026-74958)** Information disclosure in the WebRTC component
56
-
-**[CVE-2026-74959](https://www.cve.org/CVERecord?id=CVE-2026-74959)** Mitigation bypass in the Storage: Cache API component
57
-
-**[CVE-2026-74960](https://www.cve.org/CVERecord?id=CVE-2026-74960)** Site isolation issue in the WebExtensions component
58
-
-**[CVE-2026-74961](https://www.cve.org/CVERecord?id=CVE-2026-74961)** Side-channel in the Web Audio component
59
-
-**[CVE-2026-74962](https://www.cve.org/CVERecord?id=CVE-2026-74962)** Site isolation issue in the Networking: Cookies component
60
-
-**[CVE-2026-74963](https://www.cve.org/CVERecord?id=CVE-2026-74963)** Same-origin policy bypass in the Networking: Cookies component
61
-
-**[CVE-2026-74964](https://www.cve.org/CVERecord?id=CVE-2026-74964)** Integer overflow in the Graphics component
62
-
-**[CVE-2026-74965](https://www.cve.org/CVERecord?id=CVE-2026-74965)** Privilege escalation in the Shell Integration component
63
-
-**[CVE-2026-74966](https://www.cve.org/CVERecord?id=CVE-2026-74966)** Information disclosure in the Form Autofill component
64
-
-**[CVE-2026-74967](https://www.cve.org/CVERecord?id=CVE-2026-74967)** Same-origin policy bypass in the Audio/Video: Playback component
65
-
-**[CVE-2026-74968](https://www.cve.org/CVERecord?id=CVE-2026-74968)** Site isolation issue in the Graphics: WebRender component
66
-
-**[CVE-2026-74969](https://www.cve.org/CVERecord?id=CVE-2026-74969)** Use-after-free in the Layout: Text and Fonts component
67
-
-**[CVE-2026-74970](https://www.cve.org/CVERecord?id=CVE-2026-74970)** Site isolation issue in the Graphics component
68
-
-**[CVE-2026-74971](https://www.cve.org/CVERecord?id=CVE-2026-74971)** Information disclosure in the DOM: UI Events & Focus Handling component
69
-
-**[CVE-2026-74972](https://www.cve.org/CVERecord?id=CVE-2026-74972)** Information disclosure in the DOM: Push Subscriptions component
70
-
-**[CVE-2026-74973](https://www.cve.org/CVERecord?id=CVE-2026-74973)** Race condition, use-after-free in the Graphics component
71
-
-**[CVE-2026-74974](https://www.cve.org/CVERecord?id=CVE-2026-74974)** Same-origin policy bypass in the Graphics: ImageLib component
72
-
73
-
Low severity:
74
-
75
-
-**[CVE-2026-74976](https://www.cve.org/CVERecord?id=CVE-2026-74976)** JIT miscompilation in the JavaScript Engine: JIT component
76
-
-**[CVE-2026-74977](https://www.cve.org/CVERecord?id=CVE-2026-74977)** Integer overflow in the Graphics component
77
-
-**[CVE-2026-74978](https://www.cve.org/CVERecord?id=CVE-2026-74978)** Clickjacking issue in the Widget component
78
-
-**[CVE-2026-74979](https://www.cve.org/CVERecord?id=CVE-2026-74979)** Mitigation bypass in the Add-ons Manager component
79
-
-**[CVE-2026-74981](https://www.cve.org/CVERecord?id=CVE-2026-74981)** Site isolation issue in the Audio/Video: Web Codecs component
80
-
-**[CVE-2026-74982](https://www.cve.org/CVERecord?id=CVE-2026-74982)** Denial-of-service in the Widget component
81
-
-**[CVE-2026-74983](https://www.cve.org/CVERecord?id=CVE-2026-74983)** Mitigation bypass in the Data Loss Prevention component
82
-
-**[CVE-2026-74984](https://www.cve.org/CVERecord?id=CVE-2026-74984)** Race condition in the JavaScript Engine component
83
-
-**[CVE-2026-74985](https://www.cve.org/CVERecord?id=CVE-2026-74985)** Privilege escalation in the Enterprise Policies component
84
-
-**[CVE-2026-74986](https://www.cve.org/CVERecord?id=CVE-2026-74986)** Site isolation issue in the CSS Parsing and Computation component
0 commit comments