Announced
July 14, 2026
Impact critical
Products
Firefox
Fixed in Firefox 152.0.6
…
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.
As always, it usually takes a little bit for updates to find their way through the build system. If you need the patch now, then using packages from Mozilla or the flatpak is the way to get it more quickly. But usually when a fix is announced it takes a little bit for it to work its way through any distribution’s build process.
You posted this with a tag of “Leap-16”. I’ll note that Leap is using the ESR version of firefox. Maybe there’s also a security problem there, but I’ll be waiting to hear about advice for the ESR version.
New FF ESR is not released yet (the latest is 140.12.0esr) - possibly it has no such flaws.
Newer Firefox (152.x) is available for Leap from openSUSE with Mozilla experimental repo.
@Svyatko Just remember that on Leap, version numbers mean diddly squat as many fixes are backported to existing versions. One must check the changelogs or patch info/descriptions on fixes as well… I use Chrome on Leap/Tumbleweed, firefox left the building many years ago here…
I would not use the devel repos, they can be in an inconsistent state when in the process of packaging a new version.
If I need the non-esr version on Leap, I would use the flatpak one.