Executive brief
Mozilla has identified multiple memory safety vulnerabilities in the Firefox web browser and Thunderbird email client. These flaws could allow an attacker to potentially execute unauthorized code on a user's computer if they visit a malicious website or open a specially crafted email. Users are advised to update to the latest versions to protect their data and system integrity.
Technical details
This advisory covers a collection of memory safety bugs (CVE-2026-12326) identified through internal testing and fuzzing. The vulnerabilities stem from memory corruption issues within the browser engine, which Mozilla developers presume could be leveraged for arbitrary code execution with sufficient exploit development effort. The attack vector typically involves a user navigating to a malicious webpage or processing malicious content in Thunderbird, requiring no special privileges but some user interaction. These issues were addressed by improving memory handling and safety checks in the affected components. Patches are available in Firefox 152 and Thunderbird 152.
Affected products
- Mozilla Firefox 151
- Mozilla Thunderbird 151
Timeline
- 2026-06-16: advisory: Mozilla Foundation Security Advisory 2026-57 published.
- 2026-06-16: patched: Fixed in Firefox 152 and Thunderbird 152.
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1767455%2C2004308%2C2024445%2C2028182%2C2029765%2C2029883%2C2030110%2C2030149%2C2030366%2C2030374%2C2030564%2C2031120%2C2033411%2C2038695%2C2042465%2C2042781%2C2042907
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2021955%2C2025960%2C2029066%2C2029403%2C2029435%2C2029803%2C2030570%2C2030573%2C2032264%2C2033234%2C2034816%2C2035907%2C2035963%2C2036895%2C2036898%2C2036907%2C2036909%2C2036928%2C2036931%2C2036932%2C2036934%2C2039238%2C2039463
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2039050%2C2042718%2C2042760%2C2044831%2C2045307%2C2045398%2C2045516%2C2045572%2C2041741%2C2044433
- https://www.mozilla.org/security/advisories/mfsa2026-57/