tlder@devFirefox 154 lands with 58 CVE fixes, twenty of them high
tlder@dev:~$
Security/CVEs/Advisories

Firefox 154 lands with 58 CVE fixes, twenty of them high

  • Shipped
  • Action required
  • High importance

Firefox 154 shipped the same day as Chrome's patch, and it carries the heavier load on paper: 58 CVEs, twenty of them rated high. Roughly half are memory-safety issues, the usual mix of use-after-free and buffer handling that Mozilla groups into a couple of catch-all advisories every cycle. The high-severity set also includes several privilege-escalation flaws, a sandbox escape, and a site-isolation bug. None are flagged as exploited in the wild yet, so this is routine hygiene rather than a fire drill. Take the update anyway — memory-safety criticals in a browser have a short shelf life before someone writes the exploit.