Security update for MozillaFirefox, MozillaFirefox-branding-SLE
This update for MozillaFirefox, MozillaFirefox-branding-SLE fixes the following issues:
This is the Firefox Extended Support Release 140.0esr ESR
Major changes:
General:
new options for character spacing, word spacing, and text
alignment. These changes offer a more accessible reading
experience.
and Gray options. You can also select custom colors for text,
background, and links from the Custom tab.
grant permissions to sites (e.g. geolocation). Temporary
permissions will be removed either after one hour or when the
tab is closed.
abusing the history API by generating excessive history
entries, which can make navigating with the back and forward
buttons difficult by cluttering the history. This
intervention ensures that such entries, unless interacted
with by the user, are skipped when using the back and forward
buttons.
into hyperlinks.
tabstrip context menu on macOS and Linux.
only the current tab if the Quit keyboard shortcut is used
while multiple tabs are open in the window. (bmo#None)
Sidebar and Tabs:
> General > Browser Layout to quickly access multiple tools
in one click, without leaving your main view. Sidebar tools
include an AI chatbot of your choice, bookmarks, history, and
tabs from devices you sync with your Mozilla account.
to quickly scan your list of tabs. With vertical tabs, your
open and pinned tabs appear in the sidebar instead of along
the top of the browser. To turn on vertical tabs, right-click
on the toolbar near the top of the browser and select Turn on
Vertical Tabs. If you’ve enabled the updated sidebar, you can
also go to Customize sidebar and check Vertical tabs. Early
testers report feeling more organized after using vertical
tabs for a few days.
related tabs together. One simple way to create a group is to
drag a tab onto another, pause until you see a highlight,
then drop to create the group. Tab groups can be named,
color-coded, and are always saved. You can close a group and
reopen it later.
background tabs, making it easier to locate the desired tab
without needing to switch tabs.
opened via the Tab overview menu.
Security & Privacy:
address bar on non-local sites. If a site is not available
via HTTPS, Firefox will fall back to HTTP.
Tracking Protection's Strict mode is enabled.
Tracking Protection, which is now available in Enhanced
Tracking Protection's 'Strict' mode. This feature detects
bounce trackers based on their redirect behavior and
periodically purges their cookies and site data to block
tracking.
web servers to provide sufficient proof that their
certificates were publicly disclosed before they will be
trusted. This only affects servers using certificates issued
by a certificate authority in Mozilla's Root CA Program.
certain social media embeds that are blocked in ETP Strict
and Private Browsing modes. Currently, support is limited to
a few embed types, with more to be added in future updates.
gracefully falls back to HTTP if the secure connection fails.
This behavior is known as HTTPS-First.
'Copy Clean Link' to help clarify expectations around what
the feature does. 'Copy Clean Link' is a list based approach
to remove - known tracking parameters from links. This option
can also now be used on plain text links.
clearing saved form info separately from browsing history.
Translations:
different languages after a full-page translation.
ex
SUSE-SU-2025:02339-1 is recorded against 2 packages.
Published on 17 July 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| mozillafirefox | — | 140.0-112.270.2 |
| mozillafirefox-branding-sle | — | 140-35.19.5 |
References
Similar Threats
Free Vulnerability Check
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:02339-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.