Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mozilla Addresses 37 Security Flaws with Firefox 149 Release

Mozilla Addresses 37 Security Flaws with Firefox 149 Release

Posted on March 25, 2026 By CWS

Mozilla has rolled out Firefox 149 on March 24, 2026, introducing a significant security update that addresses a total of 37 vulnerabilities. This update, under advisory MFSA 2026-20, marks one of the most substantial security bulletins issued for the browser, aiming to rectify issues ranging from memory corruption to remote code execution.

High-Severity Vulnerabilities in Firefox 149

The recent patch deals with vulnerabilities distributed across three levels of severity: 16 are categorized as high, 17 as moderate, and 4 as low. Notably, six sandbox escape vulnerabilities have been patched, which are critical as they allow attackers to execute arbitrary code outside Firefox’s secure environment.

A noteworthy vulnerability, CVE-2026-4684, involves a race condition paired with a use-after-free in the Graphics: WebRender component. This flaw, along with others like CVE-2026-4687 through CVE-2026-4690, represents significant threats due to their potential to bypass sandboxing mechanisms.

AI Contributions to Vulnerability Discovery

In a significant advancement, a research team employing AI tools, specifically Claude from Anthropic, contributed to identifying several vulnerabilities. These include CVE-2026-4702, a Just-In-Time (JIT) miscompilation issue, and various WebRTC signaling defects. This marks a milestone as the first instance of AI-assisted identification of multiple CVEs in a major browser update.

Other high-risk issues addressed involve memory safety bugs, such as CVE-2026-4720, CVE-2026-4721, and CVE-2026-4729, which have the potential for memory corruption and arbitrary code execution, underscoring the critical nature of these updates.

Moderate and Low Severity Issues

The patch also addresses moderate-severity issues affecting components like Canvas2D, Graphics, and the JavaScript Engine. CVE-2026-4725, for instance, is a sandbox escape vulnerability reported in the Canvas2D component.

Low-severity flaws include denial-of-service vulnerabilities and a spoofing issue in the Privacy: Anti-Tracking component. These lower-tier vulnerabilities, while less critical, still pose risks that are mitigated by this comprehensive update.

All Firefox users, including those on ESR versions 140.9 and 115.34, are encouraged to update to Firefox 149 to safeguard against these vulnerabilities. The update is available through Firefox’s built-in updater or directly from Mozilla’s website. Organizations, particularly those managing enterprise setups, should prioritize these updates due to the presence of several high-risk vulnerabilities.

Stay informed on the latest cybersecurity developments by following us on Google News, LinkedIn, and X. For more stories or inquiries, feel free to contact us.

Cyber Security News Tags:browser security, CVE vulnerabilities, Cybersecurity, memory corruption, Mozilla Firefox, remote code execution, sandbox escape, security update, software patch, Vulnerabilities

Post navigation

Previous Post: Apple Updates iOS, macOS with Critical Security Fixes
Next Post: GlassWorm Malware Exploits Solana for Data Theft

Related Posts

Critical Cisco Vulnerability Let Remote Attackers Execute Arbitrary Code on Firewalls and Routers Critical Cisco Vulnerability Let Remote Attackers Execute Arbitrary Code on Firewalls and Routers Cyber Security News
Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network Hackers Trapped in Resecurity’s Honeypot During Targeted Attack on Employee Network Cyber Security News
Cyber Attacks on IP Cameras Surge Amid Middle East Tensions Cyber Attacks on IP Cameras Surge Amid Middle East Tensions Cyber Security News
MediaTek Vulnerabilities Let Attackers Escalate Privileges Without User Interaction MediaTek Vulnerabilities Let Attackers Escalate Privileges Without User Interaction Cyber Security News
North Korean Hackers Make History with  Billion Crypto Heist in 2025 North Korean Hackers Make History with $2 Billion Crypto Heist in 2025 Cyber Security News
WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Advances Cyber Threats, But Identity Remains Key
  • AI Security Innovations Shine at 2026 Cyber Awards
  • Onit Security Secures $11M for Advanced Cyber Solutions
  • Microsoft 365 Device Code Phishing Targets Over 340 Organizations
  • Firefox 149.0 Introduces Free VPN with 50GB Limit

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Advances Cyber Threats, But Identity Remains Key
  • AI Security Innovations Shine at 2026 Cyber Awards
  • Onit Security Secures $11M for Advanced Cyber Solutions
  • Microsoft 365 Device Code Phishing Targets Over 340 Organizations
  • Firefox 149.0 Introduces Free VPN with 50GB Limit

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark