Mozilla released Firefox 157 with fixes for 76 vulnerabilities, including 38 rated high severity. The high-severity issues include memory-safety flaws that could allow attacker-controlled code execution if a user opens a specially crafted web page; Mozilla reported no vulnerabilities rated critical and the available advisories do not identify active exploitation.
Mozilla also issued security updates for Firefox ESR 153.4.0, 140.17.0, and 115.42.0. Users and administrators running earlier Firefox or ESR versions should upgrade promptly. Firefox 157 additionally introduces the experimental Nova sidebar interface, enables AV1 screen sharing support in WebRTC, and includes CSS and JavaScript dialog improvements.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Mozilla published a security advisory covering the vulnerabilities fixed in Firefox 157 and the corresponding ESR releases. Guyana National CIRT advised users and administrators to review and apply the updates where necessary.
Firefox 157 remediates 76 vulnerabilities, including 38 rated high severity; none were classified as critical. Some high-severity issues are memory-safety flaws that could potentially permit code execution if a victim opens a specially crafted web page.
Mozilla released Firefox 157 along with Firefox ESR 153.4/153.4.0, 140.17/140.17.0, and 115.42/115.42.0. The updates address vulnerabilities affecting earlier Firefox and ESR versions.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
opennet.me
Open sourceopennet.ru
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.