Executive brief
Mozilla has released security updates for Firefox and Firefox ESR to address a memory safety vulnerability. Firefox is a widely used web browser, and vulnerabilities of this type can potentially allow an attacker to crash the browser or execute unauthorized code if a user visits a malicious website. This could lead to the theft of sensitive information or unauthorized access to the user's computer.
Technical details
A memory safety vulnerability was identified in Mozilla Firefox and Firefox ESR. While specific details of the bug (Bug 2038302) are restricted, Mozilla classifies it as a memory safety bug that could potentially lead to memory corruption. In a typical browser context, such vulnerabilities are reachable via the processing of malicious web content over the network. If successfully exploited, an attacker could achieve arbitrary code execution within the context of the browser process. The issue is resolved in Firefox 152 and Firefox ESR 140.12.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched