Executive brief
A memory management vulnerability exists in the Mozilla Firefox web browser's networking component. If exploited, this could allow an attacker to potentially crash the browser or execute unauthorized code on a user's system when they visit a malicious website. This poses a risk to the confidentiality and integrity of user data and the stability of the application.
Technical details
A use-after-free vulnerability was identified in the Networking: HTTP component of Mozilla Firefox. The flaw occurs when the browser continues to use a memory pointer after it has been freed, typically during the processing of HTTP network traffic. An attacker could exploit this by enticing a user to visit a specially crafted webpage, potentially leading to a heap corruption and arbitrary code execution within the context of the browser process. The vulnerability is fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12, < 115.37
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory