Executive brief
Mozilla has released security updates for Firefox and Firefox ESR to address a memory safety vulnerability. This type of flaw occurs when the software incorrectly handles data in the computer's memory, which could potentially allow an attacker to crash the browser or execute unauthorized code. Users are advised to update to the latest versions to protect their systems and data from potential exploitation.
Technical details
A memory safety vulnerability was identified in Mozilla Firefox and Firefox ESR. While specific technical details are restricted in the associated Bugzilla report (Bug 2041981), Mozilla classifies this as a high-impact memory safety bug. Such vulnerabilities typically involve memory corruption issues like buffer overflows or use-after-free conditions. If successfully exploited, an attacker could potentially achieve arbitrary code execution within the context of the browser process. The issue is resolved in Firefox 152 and Firefox ESR 140.12.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory