Executive brief
Mozilla Firefox and Firefox ESR are popular web browsers used to access the internet. Multiple memory safety vulnerabilities were discovered that could allow an attacker to corrupt the browser's memory. If successfully exploited, these flaws could allow an attacker to execute unauthorized code on a user's computer, potentially leading to data theft or full system compromise.
Technical details
This advisory covers a collection of memory safety bugs (CVE-2026-16412) identified through fuzzing and internal security audits. The vulnerabilities exhibit evidence of memory corruption, which typically includes classes such as buffer overflows, use-after-free, or out-of-bounds writes. An attacker could potentially exploit these flaws by enticing a user to visit a specially crafted malicious website. Successful exploitation could lead to arbitrary code execution within the context of the browser process. The issues are resolved in Firefox 153 and Firefox ESR 140.13.
Affected products
- Mozilla Firefox 152
- Mozilla Firefox ESR 140.12
Timeline
- 2026-07-21: advisory
- 2026-07-21: patched
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2005113%2C2025369%2C2026301%2C2028663%2C2029761%2C2042242%2C2043271%2C2043300%2C2044612%2C2045378%2C2045406%2C2045407%2C2045616%2C2045626%2C2045730%2C2045732%2C2045769%2C2045771%2C2047957%2C2048934%2C2049818%2C2049822%2C2050151%2C2050368%2C2051653%2C2051658
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2043035%2C2045057%2C2045187%2C2045402%2C2045417%2C2045482%2C2045611%2C2045618%2C2045756%2C2046917%2C2047718
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045413%2C2053635%2C2053637
- https://www.mozilla.org/security/advisories/mfsa2026-68/
- https://www.mozilla.org/security/advisories/mfsa2026-70/