Junglewise Threat Intelligence

CVE-2026-12301: Mozilla Firefox memory safety bug

CVE-2026-12301 · Severity: info · CVSS 6.5 · Published 2026-06-16

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla has released a security update for Firefox to address a memory safety vulnerability. This type of flaw occurs in the web browser used by employees to access the internet and internal applications. If exploited, a malicious website could potentially crash the browser or execute unauthorized code on the user's computer, leading to data theft or further system compromise.

Technical details

Mozilla reported a memory safety bug in Firefox versions prior to 152. While specific details of the memory corruption are restricted in the associated Bugzilla report (Bug 2015647), Mozilla classifies these types of vulnerabilities as having the potential for memory corruption that could be leveraged for arbitrary code execution. The attack vector typically involves a user visiting a specially crafted malicious webpage (Remote Code Execution via memory corruption). The vulnerability is resolved in Firefox 152.

Affected products

  • Mozilla Firefox < 152

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched

References

Related threats