Junglewise Threat Intelligence

CVE-2026-12327: Mozilla Firefox and Thunderbird memory safety bugs

CVE-2026-12327 · Severity: info · Published 2026-06-16

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular web browser and email applications. Multiple memory safety issues were identified that could potentially allow an attacker to crash the application or execute unauthorized code on a user's computer. This typically occurs if a user visits a malicious website or opens a specially crafted email.

Technical details

This advisory covers a collection of memory safety bugs identified through fuzzing and internal code review. The vulnerabilities manifest as memory corruption within the browser engine. While the specific root causes (e.g., buffer overflows, use-after-free) vary across the reported bugs, Mozilla developers presume that with sufficient effort, some could be leveraged for arbitrary code execution. The attack vector is typically remote, requiring a user to process malicious web content or email. These issues are resolved in Firefox 152, Firefox ESR 140.12, and the corresponding Thunderbird releases.

Affected products

  • Mozilla Firefox ESR 140.11
  • Mozilla Thunderbird ESR 140.11
  • Mozilla Firefox 151
  • Mozilla Thunderbird 151

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched

References

Related threats