Executive brief
A security vulnerability has been identified in the Mozilla Firefox web browser's security component. This flaw allows an attacker to bypass built-in security mitigations, potentially leading to unauthorized access to data or further exploitation. Users are advised to update to the latest versions of Firefox or Firefox ESR to protect their browsing sessions and personal information.
Technical details
A mitigation bypass vulnerability exists in the DOM: Security component of Mozilla Firefox. The flaw allows for the circumvention of security measures designed to protect the Document Object Model (DOM). While specific root cause details are restricted in the associated bug report (Bug 2042058), the vulnerability is classified as a mitigation bypass, which typically involves an attacker finding a way to execute actions that should be restricted by the browser's security policy. This issue was fixed in Firefox 152 and Firefox ESR 140.12. Exploitation likely requires a user to visit a specially crafted website.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory