Junglewise Threat Intelligence

CVE-2026-12329: Mozilla Firefox ESR memory safety bug

CVE-2026-12329 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox ESR. Vendors: Mozilla.

Executive brief

Mozilla has released a security update for Firefox ESR to address a memory safety vulnerability. Firefox ESR is a version of the popular web browser designed for organizations that need extended support. If exploited, this flaw could allow an attacker to crash the browser or potentially execute unauthorized code on a user's computer, which could lead to data theft or system compromise.

Technical details

Mozilla Firefox ESR versions prior to 140.12 are affected by a memory safety vulnerability (CVE-2026-12329). While specific technical details regarding the root cause are restricted in the associated Bugzilla report, Mozilla classifies this as a high-impact memory safety bug. Such vulnerabilities typically involve memory corruption issues that, if successfully exploited via a malicious website, could allow an attacker to achieve arbitrary code execution within the context of the browser process. Users are advised to update to Firefox ESR 140.12 or later to mitigate this risk.

Affected products

  • Mozilla Firefox ESR Before 140.12

Timeline

  • 2026-06-16: advisory: Mozilla Foundation Security Advisory 2026-58 published.
  • 2026-06-16: patched: Fixed in Firefox ESR 140.12.

References

Related threats