Executive brief
Mozilla has released security updates to address multiple memory safety vulnerabilities in Firefox ESR. These flaws could allow an attacker to corrupt the browser's memory by convincing a user to visit a specially crafted website. If successfully exploited, these bugs could lead to the execution of unauthorized code on the user's system, potentially compromising sensitive data or giving an attacker control over the device.
Technical details
Mozilla developers and the fuzzing team identified several memory safety bugs in Firefox ESR 115.37 and 140.12. These vulnerabilities are classified as memory corruption issues where, through unspecified memory safety errors, an attacker could potentially achieve arbitrary code execution. The attack vector is typically remote, triggered when the browser processes malicious web content. While specific root causes for each bug in this cluster are not detailed, they were identified through internal fuzzing and are presumed to be exploitable with sufficient effort. The issues are resolved in Firefox ESR versions 115.38 and 140.13.
Affected products
- Mozilla Firefox ESR 115.37, 140.12
Timeline
- 2026-07-21: advisory
- 2026-07-21: patched