Junglewise Threat Intelligence

CVE-2026-12330: Mozilla Firefox ESR incorrect boundary conditions in Internationalization

CVE-2026-12330 · Severity: info · CVSS 6.5 · Published 2026-06-16

Technologies: Mozilla Firefox ESR. Vendors: Mozilla.

Executive brief

Mozilla Firefox ESR is a web browser designed for organizations that need extended support. A vulnerability in the browser's internationalization component could allow a malicious website to cause unexpected behavior or potentially access sensitive information. This issue has been resolved in the latest security updates for the Extended Support Release (ESR) versions.

Technical details

A vulnerability exists in the Internationalization component of Mozilla Firefox ESR due to incorrect boundary conditions. While specific exploitation details are restricted in the associated bug report (Bug 2029326), this class of vulnerability typically involves buffer overflows or out-of-bounds access when processing localized content or character sets. An attacker could exploit this by enticing a user to visit a specially crafted website, potentially leading to a process crash or unauthorized memory access. The issue is addressed in Firefox ESR 140.12 and Firefox ESR 115.37.

Affected products

  • Mozilla Firefox ESR < 140.12, < 115.37

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched

References

Related threats