Executive brief
Mozilla has released security updates for Firefox and Firefox ESR to address a memory safety vulnerability. This type of flaw occurs in the web browser, which is used to access internet resources and internal web applications. If exploited, this vulnerability could potentially allow an attacker to crash the browser or execute unauthorized code on a user's system, leading to data theft or further system compromise.
Technical details
Mozilla reported a memory safety bug (CVE-2026-12310) in Firefox and Firefox ESR. While specific technical details of the root cause are restricted in the associated Bugzilla report (Bug 2039707), Mozilla classifies it as a memory safety vulnerability that could potentially be exploited for memory corruption. In a browser context, such vulnerabilities are typically triggered by processing specially crafted web content. If successfully exploited, an attacker could achieve arbitrary code execution within the context of the browser process. The vulnerability is resolved in Firefox 152 and Firefox ESR 140.12.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory