Executive brief
Mozilla has released security updates for Firefox to address a memory safety vulnerability. This type of flaw occurs in the web browser, which is used to access internet content and internal web applications. If exploited, a malicious website could potentially crash the browser or execute unauthorized code on the user's computer, leading to data theft or system compromise.
Technical details
A memory safety vulnerability was identified in Mozilla Firefox and Firefox ESR. While specific technical details of the root cause are restricted in the associated bug report (Bug 2037290), Mozilla classifies this as a memory safety bug that could potentially be exploited for arbitrary code execution if memory corruption occurs. The attack vector typically involves a user visiting a specially crafted malicious webpage (Remote Code Execution via web content). The vulnerability is fixed in Firefox 152 and Firefox ESR 140.12.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory