Skip to content

⛐ It's the "exploit code's already out there" release!

Choose a tag to compare

@SyntaxError-PEBKAC SyntaxError-PEBKAC released this 22 Jul 06:19
· 35 commits to main since this release
d221282

🔄 Updated to Firefox ESR 140.13.0. Pure upstream sync; no ducksteps-side changes this round.

🛡️ Addressed 32 CVEs from Mozilla Foundation Security Advisory 2026-70 (July 21, 2026). Two critical this cycle (a WebAssembly invalid pointer and a DOM Navigation site isolation bypass), both with public exploit code, though Mozilla reports no confirmed in-the-wild attacks yet. Also 16 high-severity patches (three sandbox escapes, two JIT miscompilations, four WebAssembly-related bugs), 13 moderate, 1 low. Heaviest cycle since 140.12.0's 29.

Critical severity:

  • CVE-2026-15718 invalid pointer in the JavaScript: WebAssembly component (public exploit code exists)
  • CVE-2026-15719 site isolation issue in the DOM: Navigation component (public exploit code exists)

High severity:

  • CVE-2026-16349 same-origin policy bypass in the DOM: Navigation component
  • CVE-2026-16350 incorrect boundary conditions in the Audio/Video: cubeb component
  • CVE-2026-16351 sandbox escape via use-after-free in the DOM: Navigation component
  • CVE-2026-16352 sandbox escape via use-after-free in the Disability Access APIs component
  • CVE-2026-16353 invalid pointer in the DOM: Bindings (WebIDL) component
  • CVE-2026-16354 information disclosure in the Graphics: ImageLib component
  • CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component
  • CVE-2026-16356 sandbox escape via use-after-free in the Disability Access APIs component (second instance)
  • CVE-2026-16357 incorrect boundary conditions in the Graphics component
  • CVE-2026-16360 memory safety bugs shared across ESR 115.38, ESR 140.13, and Firefox 153
  • CVE-2026-16361 memory safety bugs shared across ESR 115.38 and ESR 140.13
  • CVE-2026-16362 use-after-free in the WebRTC: Audio/Video component
  • CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component
  • CVE-2026-16368 incorrect boundary conditions in the JavaScript: WebAssembly component
  • CVE-2026-16369 integer overflow in the JavaScript: WebAssembly component
  • CVE-2026-16412 memory safety bugs shared across ESR 140.13 and Firefox 153

Moderate severity:

Low severity:

  • CVE-2026-16405 information disclosure in the Networking: WebSockets component

✅ SHA512:

ducksteps.140.13.0.Setup.exe
3d10ac167d5be95e29dcba1a6c61ac5a09f5c1e467a6ec1ecd4a3770e10ec0d0b0045893c48090dab01a9dd8ed72ea754d7090c9c2e6bc22232f00aa9f9afa27

ducksteps.140.13.0.Standalone.7z
50589d1403c15ab8ff3239151ef2a739ce04387a860e12384c0ea4731a2ea42b9fae1c9df3b29ee923d82722846fa188c6db932b39bc922976566a2071f81b4f

ducksteps.140.13.0.Legacy.Setup.exe
6ce6e61ce204af7afb6dee1dc274f93ef46fbc8befde3c91627c2ef21d0a6604ec2e639e1a3c2fcec46f1e1a99ff9c9d960a3eb970c513f8003c580d55a7d360

ducksteps.140.13.0.Legacy.Standalone.7z
9d9c960e66389e94be1e847de5497a474dc86c05223a0f41ef227b3724fdedefaa909069b254b0351f70ede183186152a7283c14821f77a7cbd1baac833e1b8f


🚨 VirusTotal Results:

ducksteps.140.13.0.Setup.exe

ducksteps.140.13.0.Standalone.7z

ducksteps.140.13.0.Legacy.Setup.exe

ducksteps.140.13.0.Legacy.Standalone.7z