Executive brief
Mozilla Firefox is a popular web browser used for accessing the internet. A memory safety vulnerability was identified that could potentially allow an attacker to cause a crash or execute unauthorized code if a user visits a malicious website. This issue has been resolved in version 152.
Technical details
A memory safety vulnerability was identified in Mozilla Firefox prior to version 152. While specific root cause details (such as use-after-free or buffer overflow) are not explicitly detailed in the advisory, Mozilla classifies this as a memory safety bug that could potentially lead to memory corruption. An attacker could exploit this by enticing a user to process specially crafted web content, potentially leading to arbitrary code execution or a denial-of-service (browser crash). The vulnerability is addressed in Firefox 152.
Affected products
- Mozilla Firefox < 152
Timeline
- 2026-06-16: advisory: Mozilla Foundation Security Advisory 2026-57 published.
- 2026-06-16: patched: Fixed in Firefox 152.