Header Banner
Gadget Hacks Logo
Gadget Hacks
Windows Tips
gadgethacks.mark.png
Gadget Hacks Shop Apple Guides Android Guides iPhone Guides Mac Guides Pixel Guides Samsung Guides Tweaks & Hacks Privacy & Security Productivity Hacks Movies & TV Smartphone Gaming Music & Audio Travel Tips Videography Tips Chat Apps

Firefox 153 Update: HDR Video, QR Sharing, and Critical Security Fixes

Firefox 153 Update: HDR Video, QR Sharing, and Critical Security Fixes

Firefox 153 shipped last week with a security advisory that warrants immediate attention. MFSA 2026-68 rates the release's overall security impact as high, citing memory-corruption bugs in Firefox 152 that Mozilla says could, with sufficient effort, have been exploited to run arbitrary code. The update also delivers native HDR video playback on Windows 10 and 11 for qualifying hardware, QR code tab sharing, expanded PDF editing, and tighter extension permissions.

The feature set had roughly five weeks of public testing before reaching the stable channel. Version 153.0 beta first reached beta users on June 17, 2026.

Firefox 153 features: HDR video, QR code sharing, and PDF tools

The headline addition for Windows users is HDR video support, and it comes with real hardware constraints.

Firefox 153 enables HDR video on Windows 10 and 11 for users with HDR-capable displays connected to AMD or NVIDIA discrete GPUs, per Mozilla's beta release notes. Intel-plus-NVIDIA hybrid GPU configurations are explicitly excluded for now. Mozilla confirmed support for additional GPU vendors is in progress, though no timeline was provided.

The feature requires a manual step: HDR mode must be enabled in Windows Settings > Display before anything changes visually, per Mozilla's release notes. Nothing in the browser UI flags this requirement. Firefox had already supported HDR on macOS; the Windows implementation closes a meaningful gap on the platform where the browser's installed base is largest.

Tab sharing got a low-friction shortcut. Right-clicking any tab now offers Share > Generate QR Code, letting users push a page from desktop to a mobile device in two clicks, according to Mozilla's release notes. It's a convenience feature, not a platform shift, but for anyone who regularly moves URLs between devices, it removes an obvious friction point.

The built-in PDF editor expanded in two directions. Users can now merge documents by dragging a PDF into the sidebar, and images can be inserted as new pages within an existing PDF, per Mozilla's beta notes. Neither is a dramatic capability jump, but both reduce the cases where a separate tool is needed for routine document work.

Two privacy-facing changes are worth flagging. Firefox now shows the location permission icon in red whenever a site has active access to a user's location, a persistent ambient indicator rather than something buried in a settings audit, per Mozilla's release notes. The second change is structural: extensions can no longer access local files by default. That access still exists, but users must now explicitly grant it through a new "Access local files on your computer" permission, kept separate from the broader "Access your data for all websites" toggle. Users running productivity extensions that read local documents should verify their permissions after updating.

The release also includes experimental support for the JPEG XL image format, which Mozilla says generally provides better compression than WebP, JPEG, PNG, and GIF and is designed to supersede them, per Mozilla's beta notes. Web adoption of the format remains limited, so this is more a signal of direction than a practical day-one change. Separately, Firefox now verifies and displays Qualified Website Authentication Certificates (QWACs) under the EU's eIDAS regulations. Both are real additions with narrow immediate impact for most users.

macOS users get one new addition: support for Apple's system-wide full-screen keyboard shortcut (Globe-F), per Mozilla's beta notes. Small, but the kind of thing that matters if it was conspicuously absent before.

Firefox 153 security fixes: what Mozilla patched and who needs to act

Three CVEs in MFSA 2026-68 address memory-safety bugs Mozilla says "showed evidence of memory corruption" and that the organization presumes, with sufficient effort, "could have been exploited to run arbitrary code." That language is Mozilla's own. It establishes severity without requiring outside interpretation.

The affected surface spans multiple release channels. CVE-2026-16411 covered bugs specific to Firefox 152, fixed in 153. CVE-2026-16412 affected both Firefox 152 and ESR 140.12, patched in Firefox 153 and ESR 140.13. CVE-2026-16360 had the widest reach: Firefox 152, ESR 140.12, and ESR 115.37, resolved across all three branches in Firefox 153, ESR 140.13, and ESR 115.38, per MFSA 2026-68. A fourth CVE, CVE-2026-16361, addressed memory-safety bugs present in ESR 115.37 and ESR 140.12, fixed in ESR 115.38 and ESR 140.13, per MFSA 2026-69.

Mozilla has not stated that any of these vulnerabilities were actively exploited in the wild. That distinction matters. Memory corruption rated high by the vendor is, however, a category that moves quickly from theoretical to targeted once technical details circulate.

For standard-channel users, if Firefox updates automatically, the fix is already applied. Users who manage their own update schedule should treat this as urgent.

Enterprise environments on extended support branches face a more pointed situation. ESR 115.37 and ESR 140.12 are both explicitly in scope for multiple CVEs, with fixes available now in ESR 115.38 and ESR 140.13. Organizations with extended patch cycles should treat CVE-2026-16360, the vulnerability that reached across all three branches simultaneously, as the priority item.

The Firefox 153 advisories don't exist in isolation. Earlier this year, Mozilla disclosed that Anthropic's AI-assisted red team had surfaced 14 high-severity bugs and 22 CVEs, all fixed ahead of Firefox 148. Anthropic also discovered 90 other bugs, most of which are now fixed, per Mozilla's blog post. The 153 patches aren't directly linked to that effort, but Mozilla has been running an active hardening cycle for several months, and the pattern of high-impact fixes across consecutive releases reflects it.

Who should update, and what to expect

Anyone still on Firefox 152, ESR 140.12, or ESR 115.37 should update now. The memory-safety vulnerabilities in MFSA 2026-68 carry Mozilla's high-impact rating and reach across all three release branches. The fixes are available.

Windows users with HDR displays and discrete AMD or NVIDIA GPUs get an additional payoff: native HDR video playback, once HDR mode is enabled in Windows display settings. Users on Intel-plus-NVIDIA hybrid configurations should watch for the broader GPU support Mozilla has confirmed is in progress. Everyone else gets QR sharing, improved PDF tools, and clearer location and extension permissions. The security case closes the argument on its own.

Apple's iOS 26 and iPadOS 26 updates are packed with new features, and you can try them before almost everyone else. First, check our list of supported iPhone and iPad models, then follow our step-by-step guide to install the iOS/iPadOS 26 beta — no paid developer account required.

Sponsored

Related Articles

Comments

No Comments Exist

Be the first, drop a comment!