Executive brief
A vulnerability in the Firefox web browser's image processing library could allow a malicious website to crash the application. This results in a denial-of-service, causing the browser to become unresponsive or close unexpectedly, which can disrupt user operations and lead to the loss of unsaved data. Users are advised to update to the latest versions of Firefox or Firefox ESR to resolve this issue.
Technical details
A denial-of-service (DoS) vulnerability exists in the Graphics: ImageLib component of Mozilla Firefox. The flaw is triggered when the browser processes specific image content, leading to an application crash. While the specific root cause (e.g., null pointer dereference or resource exhaustion) is not detailed in the advisory, the impact is limited to service availability. The vulnerability is reachable via the network vector without authentication, requiring only that a user navigates to a malicious site or views a malicious advertisement. This issue has been addressed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
Affected products
- Mozilla Firefox < 152
- Mozilla Firefox ESR < 140.12, < 115.37
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
- 2026-06-16: advisory