Executive brief
Mozilla Firefox is a widely used web browser. A memory safety vulnerability was identified that could allow an attacker to potentially execute unauthorized code on a user's computer if they visit a malicious website. This could lead to the theft of sensitive data or full system compromise. Users should update to the latest version of Firefox or Firefox ESR to protect their systems.
Technical details
Mozilla has addressed a memory safety vulnerability (CVE-2026-12290) in Firefox and Firefox ESR. While specific technical details are restricted in the associated Bugzilla report (Bug 2024852), Mozilla classifies this as a high-impact memory safety bug. Such vulnerabilities typically involve memory corruption issues like buffer overflows or use-after-free conditions. An attacker could exploit this by enticing a user to process specially crafted web content, potentially leading to arbitrary code execution within the context of the browser process. The issue is resolved in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12, < 115.37
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory