Junglewise Threat Intelligence

CVE-2026-12291: Mozilla Firefox use-after-free in Networking HTTP component

CVE-2026-12291 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A memory management vulnerability exists in the Mozilla Firefox web browser's networking component. If exploited, this could allow an attacker to potentially crash the browser or execute unauthorized code on a user's system when they visit a malicious website. This poses a risk to the confidentiality and integrity of user data and the stability of the application.

Technical details

A use-after-free vulnerability was identified in the Networking: HTTP component of Mozilla Firefox. The flaw occurs when the browser continues to use a memory pointer after it has been freed, typically during the processing of HTTP network traffic. An attacker could exploit this by enticing a user to visit a specially crafted webpage, potentially leading to a heap corruption and arbitrary code execution within the context of the browser process. The vulnerability is fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Firefox ESR < 140.12, < 115.37

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched
  • 2026-06-16: advisory

References

Related threats