Junglewise Threat Intelligence

CVE-2026-12312: Mozilla Firefox memory safety bug

CVE-2026-12312 · Severity: info · CVSS 6.5 · Published 2026-06-16

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla has released security updates to address a memory safety vulnerability in the Firefox web browser. If a user visits a specially crafted malicious website, this flaw could potentially allow an attacker to crash the browser or execute unauthorized code on the user's computer. This could lead to the theft of sensitive information or the installation of malware.

Technical details

Mozilla reported a memory safety bug (CVE-2026-12312) in Firefox and Firefox ESR. While specific technical details are restricted in the associated Bugzilla report (Bug 2040383), Mozilla classifies this as a memory safety vulnerability that could potentially be exploited to achieve memory corruption. In a browser context, such vulnerabilities are typically triggered via the processing of malicious web content (HTML, JavaScript, or CSS) and can lead to arbitrary code execution within the browser's process. The vulnerability is resolved in Firefox 152 and Firefox ESR 140.12.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Firefox ESR < 140.12

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched

References

Related threats