Mozilla published MFSA 2026-97 with Firefox 157 on September 29, 2026. It classifies several flaws as high impact, including memory errors, sandbox escapes and privilege escalations. CERT-FR confirms that versions before Firefox 157 and the fixed ESR branches are affected. The advisory does not report active exploitation.
What the advisory describes
Mozilla details use-after-free bugs, boundary errors, sandbox escapes and privilege escalations in components including WebGPU, DOM navigation and process sandboxing. Each advisory maps CVEs to affected components. High impact describes potential risk; it does not mean the flaws have been exploited on devices in your organisation.
Why the sandbox matters
A browser isolates web content from system privileges. A sandbox escape can weaken that boundary; combined with another flaw, it can increase the impact of malicious content. That does not mean every visited page exploits these bugs.
Update the fleet
Deploy Firefox 157 or later on the standard branch. For Firefox ESR, install the fixed version matching your branch: 153.4, 140.17 or 115.42. Check roaming devices, shared profiles and machines that connect infrequently, then verify the version after restart. Apply the same update-tracking discipline to other browsers, as covered in our article on the Chrome 154 security update.
Review sensitive devices
For a device that displayed suspicious content before patching, preserve available logs and request an appropriate assessment. Mozilla does not report password extraction in this advisory, so any rotation should follow evidence or an incident policy rather than an assumption. If you suspect browser data theft, see our guide to infostealers and protecting business access.
How Soclyde fits
Soclyde does not replace browser updates or EDR. It can help organise unique secrets for accounts that must be revoked or renewed after a device assessment, using a local-first encrypted vault controlled by the team.
Key takeaway
Firefox 157 and the corresponding ESR releases fix flaws that Mozilla and CERT-FR classify as high impact. Update devices and document exceptions; if an account compromise is established, prioritise which passwords to change rather than rotating every secret indiscriminately. To review the credentials your team stores, read our password manager security audit guide.



