Executive brief
Mozilla has released security updates to address multiple memory safety vulnerabilities in Firefox and Thunderbird. These applications are used for web browsing and email communication. If exploited, these flaws could allow an attacker to corrupt the application's memory, potentially leading to the execution of unauthorized code on the user's system.
Technical details
This advisory covers a collection of memory safety bugs (CVE-2026-12328) identified in various versions of Firefox and Thunderbird. The vulnerabilities are characterized by memory corruption issues discovered through internal testing and fuzzing. An attacker could potentially exploit these flaws by enticing a user to visit a malicious website or open a specially crafted email, leading to arbitrary code execution within the context of the application. The root cause involves improper memory management across several components. Patches have been released in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, and corresponding Thunderbird versions.
Affected products
- Mozilla Firefox ESR 115.36, 140.11
- Mozilla Firefox 151
- Mozilla Thunderbird ESR 140.11
- Mozilla Thunderbird 151
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029402%2C2038477%2C2039726%2C2041373%2C2042268%2C2042451%2C2042782%2C2042858%2C2042929%2C2042965%2C2043213
- https://www.mozilla.org/security/advisories/mfsa2026-57/
- https://www.mozilla.org/security/advisories/mfsa2026-58/
- https://www.mozilla.org/security/advisories/mfsa2026-59/