Executive brief
Mozilla has released security updates for Firefox and Firefox ESR to address a memory safety vulnerability. This type of flaw occurs when a program mishandles its memory, which could potentially allow an attacker to crash the browser or execute unauthorized code if a user visits a malicious website. Users should update to the latest versions to protect their data and system stability.
Technical details
A memory safety vulnerability was identified in Mozilla Firefox and Firefox ESR. While specific details of the root cause (such as buffer overflow or use-after-free) are not explicitly detailed in the advisory, Mozilla classifies it as a memory safety bug that could potentially be exploited for arbitrary code execution. The vulnerability is reachable via the network if a user processes malicious web content. The issue is resolved in Firefox 152 and Firefox ESR 140.12. An attacker would typically require user interaction, such as tricking a user into visiting a specially crafted webpage.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory