Executive brief
Mozilla Firefox is a widely used web browser. Multiple memory safety vulnerabilities were identified that could allow an attacker to corrupt the browser's memory. If successfully exploited, these flaws could allow an attacker to execute unauthorized code on a user's computer, potentially leading to data theft or full system compromise.
Technical details
This advisory covers a collection of memory safety bugs (CWE-119) identified through fuzzing and internal security audits. The vulnerabilities manifest as memory corruption within the browser engine. An attacker could exploit these flaws by enticing a user to visit a specially crafted website (network attack vector requiring user interaction). Successful exploitation could lead to arbitrary code execution within the context of the browser process. Mozilla has confirmed that some of these bugs showed evidence of memory corruption, though no active exploitation in the wild has been reported. The issues are resolved in Firefox version 152.0.4.
Affected products
- Mozilla Firefox 152.0.3
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory
- 2026-06-30: patched