32-bit
nullsoftmachine scopedownload-installer.cdn.mozilla.net · publisher-owned- File name
- Firefox Setup 153.0.3.exe
- SHA-256
- 8165fc4569aa9ea9843f3c800d019e4ebdd84d7ddd08866b800cd4518460257f
- Silent install
- /S /PreventRebootRequired=true
by Mozilla · MPL-2.0
Mozilla Firefox is free and open source software, built by a community of thousands from all over the world.
Mozilla's download button gives you a small stub installer that fetches Firefox during setup. The full installer is published openly, just not on the page most people land on.
Firefox is unusual in a good way here: Mozilla publishes complete installers for every language and platform openly, and the ones listed on this page come straight from that release infrastructure.
Each build is language-specific. Take the en-US package unless you need a different interface language, because the language is baked into the installer rather than chosen at runtime.
These URLs are the ones Mozilla declares in its own manifest. We do not proxy or shorten them, and we do not host a copy.
More than one architecture below. Check which one your Windows is if you are not sure.
Run this against the file on disk. If the output does not match the hash below, the file is not what Mozilla published. Delete it.
Windows · PowerShell
Get-FileHash "Firefox Setup 153.0.3.exe" -Algorithm SHA256macOS · Linux
shasum -a 256 "Firefox Setup 153.0.3.exe"Expected output
8de41917930c35937a46eac6d0e16c633ed7456c771b32b89dc6fd65d55e512e
Got a different hash, or one you cannot place? Paste it into the hash checker and it will tell you which program and version it belongs to, past releases included.
The unattended switch below is the one Mozilla declares in the installer manifest, not one we guessed by trying flags.
32-bit · machine scope · publisher-declared
.\Firefox Setup 153.0.3.exe /S /PreventRebootRequired=trueMozilla ships a real MSI and an MSIX for enterprise deployment, and they are not the file the download page gives you. The stub you get from mozilla.org is a downloader; the MSI is the one that installs unattended and predictably.
Configuration does not go on the command line. Firefox reads a policies.json file placed in a distribution folder next to the executable, and that is where you set the homepage, disable telemetry, pin extensions or turn off the update service. Deploying the MSI and then dropping policies.json in place is the whole procedure.
The switch above prevents the reboot prompt. Firefox does not need a reboot to install, but the installer will ask under some conditions and that stalls an unattended run.
Firefox updates itself within days, so the version you carefully deployed is not the version running next week. If you need a fixed version, set DisableAppUpdate in policies.json, and plan how you will roll updates yourself. If you do not need a fixed version, leave updates on: an out-of-date browser is a worse problem than drift.
Extended Support Release has its own installer and its own version line, and it is what most managed environments actually want. Installing regular Firefox and expecting ESR behaviour is a common and expensive mistake.
Run it from the folder holding the downloaded file, in a terminal opened as administrator when the package installs for all users. Silent means no window and no prompts, so check the exit code rather than waiting for something to appear: 0 is success and 3010 means it worked but wants a reboot.
The macOS build as Homebrew declares it, with the same treatment as the Windows side: the publisher's own URL and a hash to check it against.
| Signal | Finding | Points |
|---|---|---|
| SHA-256 hash published | 3 of 3 installers ship a SHA-256 hashWithout a published hash there is no way to prove the file you downloaded is the file the publisher built. | 30 / 30 |
| Binary provenance | 3 on a domain owned by the publisherThe strongest signal against a repackaged installer: the file should come from the publisher, not from a mirror nobody vouches for. | 35 / 35 |
| Served over HTTPS | 3 of 3 over HTTPSAn installer fetched over plain HTTP can be modified in transit. | 15 / 15 |
| Release recency | last release about 0 months agoSoftware that has not shipped in years accumulates unpatched vulnerabilities. | 15 / 15 |
| Licence declared | MPL-2.0A declared licence tells you what you are actually allowed to do with the software. | 5 / 5 |
Extensions Mozilla Firefox (en-US) registers itself to handle.
Yes, in the sense we can actually verify: the installer downloads from mozilla.net, which is a domain we have tied to Mozilla.
Every one of the 3 installers on this page comes with the SHA-256 Mozilla declared, so you do not have to take our word for it: hash the file you downloaded and compare.
What this does not tell you is whether the software itself is any good, or whether you want what it does once installed. A publisher can ship something you would rather not run and the download is still authentic. We answer the question we can measure and leave the other one to you.
If Windows says “Windows protected your PC” when you run it, that is SmartScreen reporting reputation, not a malware verdict — it shows up on perfectly legitimate software from small publishers and on releases that are simply new. The reverse matters more: no warning does not mean the file was checked.
How the 100/100 score is calculated · why the source matters more than the reputation
Windows ships with a package manager, and this program is in it. The identifier below is the one Microsoft's repository uses, which is also where the download URL and hash on this page come from.
Install
winget install --id Mozilla.Firefox --exactUpgrade later
winget upgrade --id Mozilla.FirefoxWhy --exact: without it winget matches on name as well as identifier, and a search that returns more than one package makes it stop and ask rather than install. Pinning the identifier is what makes the command safe to put in a script.
Not installing anything, or getting an error back? The commands that actually come up covers upgrading everything at once, what --include-unknown is for, and why winget can be missing from a machine that should have it.
The version history of Mozilla Firefox (en-US), each release with the download URL the publisher declared at the time and the SHA-256 to check it against. Useful when an update breaks something and you need to downgrade to a build that worked.
We do not host any of these files and never re-upload them, which is the difference between this and an old-version download site.
F48EC001B52F91CDF84B34B2743DB13D2FE6A21F20344C89B2EAFC3F963EB10C
0B557B2983D63278BE98DAF7582FBB7050F93310F2A9381E804E0BA14FE2892E
905115B96EAB601589FDF5B4CDE47DAB3D0C73EBF397C2779ACCD4076D82734C
EB28BB892E4A02392A587DE9FFC737E1D8DA77B92D5E093710CF393EF7260C19
B409FF5AF3419214F11F928E67B1F44C1AD0F8A46F7DB7E697CAEDEFA02A6D2A
CB6FCBD0D6092FCCEF5A42448776FB3EF1CC770CCB9381ACDEEFBA61359BDB81
5A1FF106CA943123BADF692712D04AE23C395A2B6C93D9BB0F1E0041FDA0DF31
3D4FCC5370BB183C9535D64B98D946C2DACF664A394EBCC02844E361D58D59B4
F19BD0523CEC38E8F92DD97F1C730AA58483AE7F018D46AB5DC332CA047F9370
755DDFC49EC3623CBA71F1ABEB76AC71DD7D0AAC928514E263105AE0CF1BB3E2
6FE5DF6FD8ABF6B9A4DE021C904FFD03CBF09DDC41AEA6D4AAF333EE39EC3373
FDA877426661E5760453674E34FA59D92771DE445AFC0ED9DBE2EADFE7993B12
5C8916F4653A166CBCC4E5147914A6A80FD0DE2FDB045E25B655076A31330094
A1CD9B563A1C084DB7E77F6E2A7E1F07876D8E58E4E33463052D53CC0A5D7069
96137281E8EEC87F77CF7322880C1042F664DF742E1BBE3537ED045991509A33
BADE9D987FB339E34336890E5699A47147A36ADEC3F8B662CAF1F0DD9ACCD708
C0824D81DB60A834FF647CA50F078C9C78F932D7E758855668FC24587F94A3D8
F7A7854D2157B1BFDF61983698D1322F12EE9B245C8180B897F0C080B21B3C82
567D274907B2E325B14C9DF2D8B9C61791159731F6A63FBFC6F698CB94A3CC42
FAD4C3EC713A63866D7DA88E03EB5A33F1A330159C9E1D8637F03D3DF60B0646
3AB94EDBE80C9D6E6179A24DB8A658DD3383D5A6054732C6E404F299450C0A0D
D9396FAB26734D1B0210D39200A1533C2ADE883FB148A793F15EF37B27BD6E88
5DA02F6D784A36BFE21A52971B09424923AA245B57A17FE77FC52225C25B99F9
F6FA9CC464D687E4AAAE5E23B41852A95AF93A587A64128D8B242651AAF19883
224EC689BF0580945F33FB526C4D8633E3427205FF5563B7DBAE5FE81ACC3BBB
3C426623FF83CB014402607C7EC99FEA5B39EEC2E44A07F639680C393FF9784E
7B6270DCBD5D6308AE3053414DC64F1A9ABB8BE9FD6171D00B92074C7D2C2F3D
E6E4D57D458F34CFC59BAEEAC79A4DE583C5E2306F0998BBEAB7B6D59C1A7C11
528CF4D62C9E627231718D2C567CB5AC290D7279C97DAAE347E8227CDEFD46EF
043746C55E59522FD7180942E6C2D2BFFDC56F225851CD613F3C0DB4464AB2D3
94C5E348A0B78ADFF6E9C5C5F174179E5F14ED372A5D4900F3E49485970CF5D6
EBEACA771401C1162DF251681111262869E7186288605702811F4A734197D3D7
C339AECAA9A0EE29423C607D6C9E13960B15DCB680F4CE3918D49A50267ABE1C
32EF1DAB8456FA5FADB5B3AF9E9B5755A3408A67473CBDA4CA81511D86EF8290
BF3AD3E5ACA6D619785393920BC02CA81B8FE50E661FB8C50F9802868E2043B1
2DBF863C1065A37B51A1002EA4526F44CBB9681FB52B8BB75036BCFBE8B8877E
41CA6008FBCAD9F02A847CA2F04B3CC0816C6A02C7A870F771499C47CEDC0DDC
1275FD22DF71BAB098C19671D6C5037C424A1594359A721BE20A642C827F6E71
E3C7B21DCE23B7093BA5DE30FF9296D0102E8A0DF12262FB5CB2583DF53868D7
B122087769837AC0E9B6D0D1E4A6A024F5B3D0E899346FE91E90C00AF6614F71
358381238A840831DA8A6CDA16721692DF91A74BC44847FF0285DA12DE788A8D
0291F34877CF898369FFA35CB208D8613AF4E998A68B20C75078EF67DADC67FC
17D3F11FF7710E1631A26EB38C7A42E6A82214E73B021CC79B427318B1FA2148
741A93557C8E47511949787F7A56D2355FD9C5A74C35506058BF89CEAED96700
525FCEEA344F7D1DCE73E34A85BE19CD89C5217651926466D282F58829C97A71
D6217BBEE5B91C1648A909DF4F92E98D004A2B1F260488A567ED4ABC632AB59E
0458E29F4F4B709B6677D07656937ABECDE7EFF2069DB19884D0FA0DDC531E83
2C6A70398E3B288AA2DBA14423D61091CF1DC9D2A4EC5499ED92AFED2C64BF69
313A2E29F6D171C606EAEC4D802787BFBB142E4258ACA28714921DCBE61A4769
21936D1C7C9667C85C4637CB832259C0E70942F4B928ED9436699F0CCFAD53BD
2CB50926A9E1F6D7471CD2BF646345348CDF81DD706B47E630C7EFC0603474CB
32B4507793CB9C72F0DE757521B70D9742192AB1AD592C0DE93EFC73B11A2D4C
7029E4B01635FCC24CA553A292AF99D88BA11E502C45C12F1A4B9C10C3757076
D38E8D061147111301BFFA02486900F4702E994719A66ACFF9903A20A93C55BC
DA60A70E8FED390AAB7EAF4F37D758143CAC4132458D145B4A8D8B5AEAE55583
15E33E214B66798971AF097753970DE1AC03ED5CFF1DD6CC865494B803669331
AA78EC60F7332A97135A6F2389C0B121D3505FF36823F1CA5A9F500C8E42DCB9
BAB4F693946FC58EFCCCE368CC8393DFC053F9619FA5AC139F18482E2BB66AA7
78D0328C3D1CFECDB6B978F69D833B66FBE3C297E2E10491F5D87811A0A4A7FA
128DEA8A945BDBFE9D4EDA91599C7B16402DB88C9B6A2602E4CBBA63878F0A27
The file names, so you can tell what you have. Their hashes are in the hash checker and in the downloadable archive.
Publishers take old builds offline without warning, so a link here can stop working even though the hash stays correct forever. If you already have the file, the hash is what matters: it tells you whether what you have is what they published.
Every Mozilla Firefox (en-US) version with a published manifest, newest first. The most recent ones are listed above with their file names and hashes.
Matched on the categories Mozilla and others declare in their own manifests, so the grouping is theirs rather than ours. Each one has its official URL and hash on the same terms as this page.
Not related to Mozilla Firefox (en-US) — just other entries, each with its own official URL and published hash.