⛐ It's the "exploit code's already out there" release!
🔄 Updated to Firefox ESR 140.13.0. Pure upstream sync; no ducksteps-side changes this round.
🛡️ Addressed 32 CVEs from Mozilla Foundation Security Advisory 2026-70 (July 21, 2026). Two critical this cycle (a WebAssembly invalid pointer and a DOM Navigation site isolation bypass), both with public exploit code, though Mozilla reports no confirmed in-the-wild attacks yet. Also 16 high-severity patches (three sandbox escapes, two JIT miscompilations, four WebAssembly-related bugs), 13 moderate, 1 low. Heaviest cycle since 140.12.0's 29.
Critical severity:
- CVE-2026-15718 invalid pointer in the JavaScript: WebAssembly component (public exploit code exists)
- CVE-2026-15719 site isolation issue in the DOM: Navigation component (public exploit code exists)
High severity:
- CVE-2026-16349 same-origin policy bypass in the DOM: Navigation component
- CVE-2026-16350 incorrect boundary conditions in the Audio/Video: cubeb component
- CVE-2026-16351 sandbox escape via use-after-free in the DOM: Navigation component
- CVE-2026-16352 sandbox escape via use-after-free in the Disability Access APIs component
- CVE-2026-16353 invalid pointer in the DOM: Bindings (WebIDL) component
- CVE-2026-16354 information disclosure in the Graphics: ImageLib component
- CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component
- CVE-2026-16356 sandbox escape via use-after-free in the Disability Access APIs component (second instance)
- CVE-2026-16357 incorrect boundary conditions in the Graphics component
- CVE-2026-16360 memory safety bugs shared across ESR 115.38, ESR 140.13, and Firefox 153
- CVE-2026-16361 memory safety bugs shared across ESR 115.38 and ESR 140.13
- CVE-2026-16362 use-after-free in the WebRTC: Audio/Video component
- CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-16368 incorrect boundary conditions in the JavaScript: WebAssembly component
- CVE-2026-16369 integer overflow in the JavaScript: WebAssembly component
- CVE-2026-16412 memory safety bugs shared across ESR 140.13 and Firefox 153
Moderate severity:
- CVE-2026-16358 site isolation issue in the Graphics: WebRender component
- CVE-2026-16359 incorrect boundary conditions in the Audio/Video: GMP component
- CVE-2026-16371 privilege escalation in the DOM: Navigation component
- CVE-2026-16374 information disclosure in the DevTools: Framework component
- CVE-2026-16375 site isolation issue in the Networking: HTTP component
- CVE-2026-16377 mitigation bypass in the PDF Viewer component
- CVE-2026-16379 privilege escalation in the DOM: Content Processes component
- CVE-2026-16381 same-origin policy bypass in the Networking: DNS component
- CVE-2026-16383 mitigation bypass in the DOM: Networking component
- CVE-2026-16387 site isolation issue in the Networking component
- CVE-2026-16390 mitigation bypass in the Enterprise Policies component
- CVE-2026-16391 information disclosure in the Storage: IndexedDB component
- CVE-2026-16396 privilege escalation in WebExtensions
Low severity:
- CVE-2026-16405 information disclosure in the Networking: WebSockets component
✅ SHA512:
ducksteps.140.13.0.Setup.exe
3d10ac167d5be95e29dcba1a6c61ac5a09f5c1e467a6ec1ecd4a3770e10ec0d0b0045893c48090dab01a9dd8ed72ea754d7090c9c2e6bc22232f00aa9f9afa27
ducksteps.140.13.0.Standalone.7z
50589d1403c15ab8ff3239151ef2a739ce04387a860e12384c0ea4731a2ea42b9fae1c9df3b29ee923d82722846fa188c6db932b39bc922976566a2071f81b4f
ducksteps.140.13.0.Legacy.Setup.exe
6ce6e61ce204af7afb6dee1dc274f93ef46fbc8befde3c91627c2ef21d0a6604ec2e639e1a3c2fcec46f1e1a99ff9c9d960a3eb970c513f8003c580d55a7d360
ducksteps.140.13.0.Legacy.Standalone.7z
9d9c960e66389e94be1e847de5497a474dc86c05223a0f41ef227b3724fdedefaa909069b254b0351f70ede183186152a7283c14821f77a7cbd1baac833e1b8f
🚨 VirusTotal Results:
ducksteps.140.13.0.Standalone.7z