Executive brief
Mozilla has released security updates for Firefox and Firefox ESR to address a memory safety vulnerability. This type of flaw occurs when a program improperly handles computer memory, which could potentially allow an attacker to cause the browser to crash or, in more severe cases, execute unauthorized code. Users are advised to update their browsers to the latest versions to maintain the security of their personal data and browsing sessions.
Technical details
A memory safety vulnerability was identified in Mozilla Firefox and Firefox ESR. While specific technical details regarding the root cause (such as buffer overflow or use-after-free) are not explicitly detailed in the advisory, Mozilla classifies it as a memory safety bug that could potentially be exploited for memory corruption. An attacker could likely trigger this vulnerability by enticing a user to visit a specially crafted website. Successful exploitation could lead to a process crash or arbitrary code execution within the context of the browser. The issue is resolved in Firefox 152 and Firefox ESR 140.12.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched