Junglewise Threat Intelligence

CVE-2026-12302: Mozilla Firefox mitigation bypass in DOM Security component

CVE-2026-12302 · Severity: info · CVSS 6.5 · Published 2026-06-16

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security flaw was identified in the Mozilla Firefox web browser that allows an attacker to bypass certain built-in security protections. This could potentially allow malicious websites to circumvent safety mechanisms designed to protect user data or prevent unauthorized actions. Users should update to the latest version of Firefox to ensure these protections are active.

Technical details

A mitigation bypass vulnerability exists in the DOM: Security component of Mozilla Firefox. The flaw allows for the circumvention of security mitigations, which are typically designed to prevent the exploitation of other vulnerabilities or enforce security boundaries within the Document Object Model (DOM). While specific root cause details are restricted in the associated bug report, the vulnerability is reachable via web content and requires no special privileges. An attacker could leverage this bypass to increase the impact of other flaws or bypass security policies. The issue is resolved in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Firefox ESR < 140.12, < 115.37

Timeline

  • 2026-06-16: advisory: Mozilla published security advisories MFSA2026-57, MFSA2026-58, and MFSA2026-59.
  • 2026-06-16: patched: Fixed in Firefox 152 and ESR releases.

References

Related threats