ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 89

  1. Blog

Firefox 157 (29 Sep 2026): 76 security fixes, CSS changes

Mozilla’s Firefox 157 (29 Sep 2026) brings a visual refresh, native dialogs that match a page’s light or dark scheme, CSS at-rule() and overscroll chain, and 76 CVEs in MFSA 2026-97. Sourced from Mozilla pages; nothing installed; no affiliate.

Aditya Challa·5 October 2026·7 min read

News
On this page
  1. Related links
  2. What shipped on 29 September
  3. The security advisory, by the numbers
  4. Web platform changes for frontend teams
  5. What this means on a product page
  6. What to do this week

Firefox 157 (29 Sep 2026): 76 security fixes and CSS changes for site owners

Mozilla first offered Firefox 157.0 to Release channel users on September 29, 2026. ShopperCove did not install Firefox 157 and did not run any test page in it. Everything below comes from Mozilla’s own pages, fetched 5 Oct 2026: the Firefox 157.0 release notes, the Firefox 157 notes for developers on MDN, and Mozilla’s security advisory MFSA 2026-97. This is the Firefox companion to the earlier ShopperCove note on Chrome 154. It is not a hands-on review of the redesign.

There is no affiliate link in this article.

Related links

  • https://www.shoppercove.com/blog/chrome-154-0-8037-97-security-update-october-2026
  • https://www.shoppercove.com/blog/chrome-devtools-ai-assistance-gemini-guide-2026
  • https://www.shoppercove.com/blog/tailwind-css-v4-migration-checklist-2026

What shipped on 29 September

The release notes lead with what Mozilla calls Firefox’s biggest visual refresh in years: a modernized look across toolbars, the sidebar, menus, and individual features, built with Mozilla’s updated design system. The same notes list:

  • New built-in themes with light and dark versions.
  • A compact mode that reduces toolbar and tab spacing to leave more room for web content.
  • Hardware AV1 decoding for WebRTC video calls on devices that support it, instead of always decoding AV1 in software.
  • A warning when Firefox is set up to record its encryption keys, shown in the site information panel and in Settings, because that setup could let other software on the computer read encrypted traffic.
  • Firefox Suggest in more countries, including Austria, Belgium, the Netherlands, Poland, Spain, Sweden, and Switzerland, among others named in the notes.

Under “Changed,” three items matter to people who build or run websites:

  • Amazon is no longer a built-in search engine. Mozilla says it can still be added as a custom search engine in search settings.
  • Native dialogs follow the page’s theme. Web page alert(), confirm(), and prompt() dialogs, the color and date pickers, and form autocomplete drop-downs now match the page’s light or dark color scheme.
  • Tab goes straight to the address bar text field, skipping the search engine button, which is still reachable with Shift+Tab.

The updated sidebar is now on for everyone. Mozilla says the previous sidebar can be restored by setting sidebar.revamp to false in about:config, that doing so also turns off vertical tabs, and that the preference stays available until the end of 2027.

The fixed list includes phone and tablet video appearing sideways or upside down in WebRTC calls, and some 8-bit HDR videos looking dull and gray on Windows. The notes also say “Various security fixes,” which is where the advisory comes in.

The security advisory, by the numbers

MFSA 2026-97 was announced September 29, 2026, with an overall impact of high, fixed in Firefox 157. ShopperCove counted the entries on that page: 76 CVEs, of which 38 are rated high, 29 moderate, and 9 low.

Read that count with Mozilla’s own note at the top of the advisory. Mozilla says it has changed how it publishes advisories: it no longer rolls all internally identified memory safety bugs into a single CVE, and now issues an advisory for every individual bug. So a bigger number here is not, by itself, proof that this release is riskier than an older one with a shorter list.

Components on the list that sit close to ordinary web pages:

  • Graphics: WebGPU, with several entries, including privilege escalation and use-after-free items.
  • JavaScript: WebAssembly, with several use-after-free entries plus a JIT miscompilation (CVE-2026-100792). A second JIT miscompilation in the JavaScript Engine (CVE-2026-100793) is listed too. Mozilla credits both to Amy Burnett of OpenAI.
  • DOM: Core & HTML, with multiple use-after-free entries, some marked as sandbox escapes.
  • Graphics: Canvas2D, XSLT, Storage: IndexedDB, and Layout: Text and Fonts, all rated high.
  • DOM: Service Workers: a moderate privilege escalation (CVE-2026-100807) and a moderate mitigation bypass (CVE-2026-100808).
  • CSS Parsing and Computation: a moderate use-after-free (CVE-2026-100815).

The advisory gives a reporter, an impact rating, and a bug number for each entry. It does not publish exploit details, and neither does this article. It also does not print CVSS scores, so none are added here.

Mozilla published separate advisories the same day for the Extended Support Release lines: MFSA 2026-98 for Firefox ESR 115.42, MFSA 2026-99 for ESR 140.17, and MFSA 2026-100 for ESR 153.4. ShopperCove did not compare those lists entry by entry with the Firefox 157 list, so do not assume they are identical.

Web platform changes for frontend teams

The MDN developer notes list a short set of shipped changes:

  • CSS at-rule() in @supports. You can test whether the browser supports a given at-rule, for example @supports at-rule(@scope). MDN says it also works in the supports() function of @import.
  • overscroll-behavior: chain. The shorthand and the block, inline, x, and y longhands accept chain, which lets scrolling pass to another scrollable area without the browser’s default overscroll effect, such as a bounce, at the boundary.
  • WebGPU TRANSIENT_ATTACHMENT texture usage, for memory-efficient attachments used only within the current render pass.
  • Web Animations fixes. Calling Animation.reverse() when playbackRate is 0 now plays the animation, and flipping playbackRate between positive and negative on a scroll-driven animation now mirrors its startTime to the other end of the timeline.
  • WebDriver BiDi. browser.setDownloadBehavior now requires destinationFolder when called with type="allowed". To restore default behavior without a folder, MDN says to pass null.
  • Extensions. alarms.clearAll() now fulfills its promise with undefined instead of a boolean.

MDN also lists experimental features that are in Firefox 157 but off by default: export * from "mod" including the default export (Nightly only), a navigate option for notifications, sanitizing HTML while parsing in the HTML Sanitizer API, and ML-KEM key encapsulation in Web Crypto (on by default in Nightly). None of those should be treated as shipped for your visitors.

What this means on a product page

Dark mode on checkout. The theme-matching change touches the parts of a page that site CSS usually cannot style: native confirm dialogs, date and color pickers, and browser autocomplete lists. If your checkout or account pages use any of these, look at them in Firefox 157 on both the light and dark versions of your pages. The release note says these now match the page’s light or dark color scheme. It does not spell out which page signal Firefox reads, so check the result rather than assuming.

Amazon search shortcut. Some shoppers used to search Amazon straight from the Firefox address bar without setting anything up. That built-in option is gone in 157, though users can add it back as a custom engine. If your site sells on Amazon too, this is a small change in how some Firefox users may reach a listing. It is not a reason to change your own pages.

Video calls and embeds. If your site embeds live video chat or support calls over WebRTC, two items apply: hardware AV1 decoding where supported, and the fix for rotated phone and tablet video.

Feature detection. at-rule() gives you a clean way to gate CSS on support for at-rules like @scope. The Firefox notes only describe Firefox. Keep a fallback for browsers you have not checked.

What to do this week

  1. Update Firefox. Make sure staff machines are on Firefox 157.0 or later. If your organization uses ESR, the matching fixed versions named by Mozilla are ESR 153.4, ESR 140.17, and ESR 115.42.
  2. Check native UI in dark mode. On checkout, sign-up, and account pages, trigger any confirm() or alert() dialog, open native date and color pickers, and look at autocomplete drop-downs on both light and dark pages.
  3. Fix test automation. If your end-to-end tests call WebDriver BiDi browser.setDownloadBehavior with type="allowed", add a destinationFolder, or pass null to restore default behavior.
  4. Review extension code. If you ship a Firefox extension that reads the return value of alarms.clearAll(), expect undefined now.
  5. Do not ship against experimental flags. Notification navigate, the sanitizer change, and ML-KEM are off by default in Release.
  6. Put the next release on the calendar. MDN’s Firefox 158 page says Firefox 158 ships on October 13, 2026, and that its notes are still a work in progress. Re-check your checkout then.

This is a different release from Chrome 154. The Chrome note linked above covers Google’s 1 October desktop security update. Patching one browser does not patch the other.

firefox 157mfsa 2026-97firefox security updatecss at-rule()overscroll-behavior chainfirefox esr 153.4webdriver bidifirefox 158

Lab evidence

What I found running this

Mozilla pages fetched 5 Oct 2026 (firefox.com 157.0 notes, MDN 157 and 158, MFSA 2026-97/98/99/100). CVE count (76: 38 high, 29 moderate, 9 low) counted by parsing the MFSA 2026-97 HTML. No browser GUI. No install, no test page, no benchmark.

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Plate 23

    A $19.99 PDF on packaging a digital product and writing the offer

    A one-time PDF for packaging a digital file and writing the offer. Pitch says $19.99. Not a page builder.

    4 Oct 2026

  • Plate 73

    Build Your Business Tonight: a visual kit before the product page, not a store theme

    A PDF launch kit for message, visuals, and a content month. Not a theme. Marketplace text says $149.

    4 Oct 2026

  • Plate 43

    VidRankr: thumbnails and short clips beside a product page, not another doodle app

    Thumbnails, short generated clips, and a scheduler. $67 once on the pricing page. Not VidToon and not InstaDoodle.

    4 Oct 2026

On this page

  1. Related links
  2. What shipped on 29 September
  3. The security advisory, by the numbers
  4. Web platform changes for frontend teams
  5. What this means on a product page
  6. What to do this week
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove