Plate 89
Firefox 157 (29 Sep 2026): 76 security fixes, CSS changes
Mozilla’s Firefox 157 (29 Sep 2026) brings a visual refresh, native dialogs that match a page’s light or dark scheme, CSS at-rule() and overscroll chain, and 76 CVEs in MFSA 2026-97. Sourced from Mozilla pages; nothing installed; no affiliate.
Aditya Challa7 min read
Firefox 157 (29 Sep 2026): 76 security fixes and CSS changes for site owners
Mozilla first offered Firefox 157.0 to Release channel users on September 29, 2026. ShopperCove did not install Firefox 157 and did not run any test page in it. Everything below comes from Mozilla’s own pages, fetched 5 Oct 2026: the Firefox 157.0 release notes, the Firefox 157 notes for developers on MDN, and Mozilla’s security advisory MFSA 2026-97. This is the Firefox companion to the earlier ShopperCove note on Chrome 154. It is not a hands-on review of the redesign.
There is no affiliate link in this article.
Related links
- https://www.shoppercove.com/blog/chrome-154-0-8037-97-security-update-october-2026
- https://www.shoppercove.com/blog/chrome-devtools-ai-assistance-gemini-guide-2026
- https://www.shoppercove.com/blog/tailwind-css-v4-migration-checklist-2026
What shipped on 29 September
The release notes lead with what Mozilla calls Firefox’s biggest visual refresh in years: a modernized look across toolbars, the sidebar, menus, and individual features, built with Mozilla’s updated design system. The same notes list:
- New built-in themes with light and dark versions.
- A compact mode that reduces toolbar and tab spacing to leave more room for web content.
- Hardware AV1 decoding for WebRTC video calls on devices that support it, instead of always decoding AV1 in software.
- A warning when Firefox is set up to record its encryption keys, shown in the site information panel and in Settings, because that setup could let other software on the computer read encrypted traffic.
- Firefox Suggest in more countries, including Austria, Belgium, the Netherlands, Poland, Spain, Sweden, and Switzerland, among others named in the notes.
Under “Changed,” three items matter to people who build or run websites:
- Amazon is no longer a built-in search engine. Mozilla says it can still be added as a custom search engine in search settings.
- Native dialogs follow the page’s theme. Web page
alert(),confirm(), andprompt()dialogs, the color and date pickers, and form autocomplete drop-downs now match the page’s light or dark color scheme. - Tab goes straight to the address bar text field, skipping the search engine button, which is still reachable with Shift+Tab.
The updated sidebar is now on for everyone. Mozilla says the previous sidebar can be restored by setting sidebar.revamp to false in about:config, that doing so also turns off vertical tabs, and that the preference stays available until the end of 2027.
The fixed list includes phone and tablet video appearing sideways or upside down in WebRTC calls, and some 8-bit HDR videos looking dull and gray on Windows. The notes also say “Various security fixes,” which is where the advisory comes in.
The security advisory, by the numbers
MFSA 2026-97 was announced September 29, 2026, with an overall impact of high, fixed in Firefox 157. ShopperCove counted the entries on that page: 76 CVEs, of which 38 are rated high, 29 moderate, and 9 low.
Read that count with Mozilla’s own note at the top of the advisory. Mozilla says it has changed how it publishes advisories: it no longer rolls all internally identified memory safety bugs into a single CVE, and now issues an advisory for every individual bug. So a bigger number here is not, by itself, proof that this release is riskier than an older one with a shorter list.
Components on the list that sit close to ordinary web pages:
- Graphics: WebGPU, with several entries, including privilege escalation and use-after-free items.
- JavaScript: WebAssembly, with several use-after-free entries plus a JIT miscompilation (CVE-2026-100792). A second JIT miscompilation in the JavaScript Engine (CVE-2026-100793) is listed too. Mozilla credits both to Amy Burnett of OpenAI.
- DOM: Core & HTML, with multiple use-after-free entries, some marked as sandbox escapes.
- Graphics: Canvas2D, XSLT, Storage: IndexedDB, and Layout: Text and Fonts, all rated high.
- DOM: Service Workers: a moderate privilege escalation (CVE-2026-100807) and a moderate mitigation bypass (CVE-2026-100808).
- CSS Parsing and Computation: a moderate use-after-free (CVE-2026-100815).
The advisory gives a reporter, an impact rating, and a bug number for each entry. It does not publish exploit details, and neither does this article. It also does not print CVSS scores, so none are added here.
Mozilla published separate advisories the same day for the Extended Support Release lines: MFSA 2026-98 for Firefox ESR 115.42, MFSA 2026-99 for ESR 140.17, and MFSA 2026-100 for ESR 153.4. ShopperCove did not compare those lists entry by entry with the Firefox 157 list, so do not assume they are identical.
Web platform changes for frontend teams
The MDN developer notes list a short set of shipped changes:
- CSS
at-rule()in@supports. You can test whether the browser supports a given at-rule, for example@supports at-rule(@scope). MDN says it also works in thesupports()function of@import. overscroll-behavior: chain. The shorthand and the block, inline, x, and y longhands acceptchain, which lets scrolling pass to another scrollable area without the browser’s default overscroll effect, such as a bounce, at the boundary.- WebGPU
TRANSIENT_ATTACHMENTtexture usage, for memory-efficient attachments used only within the current render pass. - Web Animations fixes. Calling
Animation.reverse()whenplaybackRateis0now plays the animation, and flippingplaybackRatebetween positive and negative on a scroll-driven animation now mirrors itsstartTimeto the other end of the timeline. - WebDriver BiDi.
browser.setDownloadBehaviornow requiresdestinationFolderwhen called withtype="allowed". To restore default behavior without a folder, MDN says to passnull. - Extensions.
alarms.clearAll()now fulfills its promise withundefinedinstead of a boolean.
MDN also lists experimental features that are in Firefox 157 but off by default: export * from "mod" including the default export (Nightly only), a navigate option for notifications, sanitizing HTML while parsing in the HTML Sanitizer API, and ML-KEM key encapsulation in Web Crypto (on by default in Nightly). None of those should be treated as shipped for your visitors.
What this means on a product page
Dark mode on checkout. The theme-matching change touches the parts of a page that site CSS usually cannot style: native confirm dialogs, date and color pickers, and browser autocomplete lists. If your checkout or account pages use any of these, look at them in Firefox 157 on both the light and dark versions of your pages. The release note says these now match the page’s light or dark color scheme. It does not spell out which page signal Firefox reads, so check the result rather than assuming.
Amazon search shortcut. Some shoppers used to search Amazon straight from the Firefox address bar without setting anything up. That built-in option is gone in 157, though users can add it back as a custom engine. If your site sells on Amazon too, this is a small change in how some Firefox users may reach a listing. It is not a reason to change your own pages.
Video calls and embeds. If your site embeds live video chat or support calls over WebRTC, two items apply: hardware AV1 decoding where supported, and the fix for rotated phone and tablet video.
Feature detection. at-rule() gives you a clean way to gate CSS on support for at-rules like @scope. The Firefox notes only describe Firefox. Keep a fallback for browsers you have not checked.
What to do this week
- Update Firefox. Make sure staff machines are on Firefox 157.0 or later. If your organization uses ESR, the matching fixed versions named by Mozilla are ESR 153.4, ESR 140.17, and ESR 115.42.
- Check native UI in dark mode. On checkout, sign-up, and account pages, trigger any
confirm()oralert()dialog, open native date and color pickers, and look at autocomplete drop-downs on both light and dark pages. - Fix test automation. If your end-to-end tests call WebDriver BiDi
browser.setDownloadBehaviorwithtype="allowed", add adestinationFolder, or passnullto restore default behavior. - Review extension code. If you ship a Firefox extension that reads the return value of
alarms.clearAll(), expectundefinednow. - Do not ship against experimental flags. Notification
navigate, the sanitizer change, and ML-KEM are off by default in Release. - Put the next release on the calendar. MDN’s Firefox 158 page says Firefox 158 ships on October 13, 2026, and that its notes are still a work in progress. Re-check your checkout then.
This is a different release from Chrome 154. The Chrome note linked above covers Google’s 1 October desktop security update. Patching one browser does not patch the other.
Lab evidence
What I found running this
Mozilla pages fetched 5 Oct 2026 (firefox.com 157.0 notes, MDN 157 and 158, MFSA 2026-97/98/99/100). CVE count (76: 38 high, 29 moderate, 9 low) counted by parsing the MFSA 2026-97 HTML. No browser GUI. No install, no test page, no benchmark.
Related links
Plate 23
A $19.99 PDF on packaging a digital product and writing the offer
A one-time PDF for packaging a digital file and writing the offer. Pitch says $19.99. Not a page builder.
4 Oct 2026
Plate 73
Build Your Business Tonight: a visual kit before the product page, not a store theme
A PDF launch kit for message, visuals, and a content month. Not a theme. Marketplace text says $149.
4 Oct 2026
Plate 43
VidRankr: thumbnails and short clips beside a product page, not another doodle app
Thumbnails, short generated clips, and a scheduler. $67 once on the pricing page. Not VidToon and not InstaDoodle.
4 Oct 2026