Junglewise Threat Intelligence

CVE-2026-12320: Mozilla Firefox information disclosure in Password Manager

CVE-2026-12320 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability in the Firefox web browser's Password Manager could allow sensitive information to be disclosed. Firefox is a widely used web browser, and its Password Manager is responsible for securely storing and autofilling user credentials. An exploit could potentially expose saved login information to unauthorized parties, compromising user account security.

Technical details

An information disclosure vulnerability exists in the Password Manager component of Mozilla Firefox. The flaw allows for the unintended exposure of sensitive data handled by the password management system. While specific technical root causes (such as specific API flaws or UI redressing) are not detailed in the advisory, the impact is categorized as information disclosure. The vulnerability is addressed in Firefox 152. Attackers would likely need to entice a user to visit a malicious website or interact with specific browser elements to trigger the disclosure.

Affected products

  • Mozilla Firefox < 152

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched: Fixed in Firefox 152

References

Related threats