Mozilla released Firefox 153.0 as the new Extended Support Release (ESR) for enterprises, schools, and other organizations seeking a long-term support browser baseline. The release adds initial Vulkan Video decode support, broadening hardware-accelerated playback beyond earlier Linux-focused VA-API work, and also brings HDR video playback on Windows systems with supported AMD and NVIDIA GPUs. Mozilla additionally highlighted PDF improvements and ongoing JPEG XL enablement, including experimental support carried forward from the beta cycle.
The update also includes security and privacy changes introduced during testing, including verification and display of Qualified Website Authentication Certificates (QWACs) in line with eIDAS requirements and a stricter default for browser extensions, which can no longer access local files unless users grant separate permission. Beta release notes also pointed to clearer location-permission indicators and a range of web-platform and developer updates, underscoring that Firefox 153 combines enterprise-focused stability with new media, document, and browser-hardening features.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Mozilla began making Firefox 153 Extended Support Release available on the ESR channel for enterprise users on July 21, 2026. Mozilla highlighted enterprise-focused additions including profile management, Split View, profile backup and restore, centrally manageable on-device AI features, and expanded security protections.
Mozilla released Firefox 153.0 as its latest monthly browser update. The release became the newest Extended Support Release and added features including initial Vulkan Video decode support, along with PDF, JPEG-XL, and HDR video updates.
Mozilla first offered Firefox 153.0beta to Beta channel users on June 17, 2026. The beta release notes say this build included security and privacy changes such as QWAC display support and restricting extensions from accessing local files by default without separate user permission.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcephoronix.com
Open sourcedeveloper.mozilla.org
Open sourcefirefox.com
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.