SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityFirefoxMozilla

Firefox 157 fixes high-impact security flaws

Mozilla fixes high-impact flaws in Firefox 157 and several ESR branches. See the versions to install and the risks documented in MFSA 2026-97.

By Soclyde Team

A tablet handed across a library desk before a security update

In summary

  • Mozilla published MFSA 2026-97 with Firefox 157 on September 29, 2026.
  • The advisory covers use-after-free bugs, sandbox escapes and a privilege-escalation issue.
  • Deploy Firefox 157 or the managed equivalent and check devices that remain offline.

Explore next

Soclyde resources

Article contents

Mozilla published MFSA 2026-97 with Firefox 157 on September 29, 2026. It classifies several flaws as high impact, including memory errors, sandbox escapes and privilege escalations. CERT-FR confirms that versions before Firefox 157 and the fixed ESR branches are affected. The advisory does not report active exploitation.

What the advisory describes

Mozilla details use-after-free bugs, boundary errors, sandbox escapes and privilege escalations in components including WebGPU, DOM navigation and process sandboxing. Each advisory maps CVEs to affected components. High impact describes potential risk; it does not mean the flaws have been exploited on devices in your organisation.

Why the sandbox matters

A browser isolates web content from system privileges. A sandbox escape can weaken that boundary; combined with another flaw, it can increase the impact of malicious content. That does not mean every visited page exploits these bugs.

Update the fleet

Deploy Firefox 157 or later on the standard branch. For Firefox ESR, install the fixed version matching your branch: 153.4, 140.17 or 115.42. Check roaming devices, shared profiles and machines that connect infrequently, then verify the version after restart. Apply the same update-tracking discipline to other browsers, as covered in our article on the Chrome 154 security update.

Review sensitive devices

For a device that displayed suspicious content before patching, preserve available logs and request an appropriate assessment. Mozilla does not report password extraction in this advisory, so any rotation should follow evidence or an incident policy rather than an assumption. If you suspect browser data theft, see our guide to infostealers and protecting business access.

How Soclyde fits

Soclyde does not replace browser updates or EDR. It can help organise unique secrets for accounts that must be revoked or renewed after a device assessment, using a local-first encrypted vault controlled by the team.

Key takeaway

Firefox 157 and the corresponding ESR releases fix flaws that Mozilla and CERT-FR classify as high impact. Update devices and document exceptions; if an account compromise is established, prioritise which passwords to change rather than rotating every secret indiscriminately. To review the credentials your team stores, read our password manager security audit guide.

Frequently asked questions

Did Mozilla report active exploitation?

MFSA 2026-97 describes several high-impact flaws but does not report active exploitation. CERT-FR recommends installing the fixed versions; severity alone does not establish that an attack is underway.

Which version should be installed?

For the standard release, install Firefox 157 or later. For ESR, Mozilla lists Firefox ESR 153.4, 140.17 or 115.42, depending on the branch in use. Verify the installed version after restarting the browser.

Are saved passwords affected?

Mozilla does not report saved-password extraction in MFSA 2026-97. Update the browser; change passwords only if compromise evidence, a service notification or your incident process warrants it.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading