Executive brief
A vulnerability exists in the Windows-specific interface component of the Firefox web browser. If exploited, this flaw could allow a malicious website to cause memory-related errors or potentially crash the browser. Users are advised to update to the latest versions of Firefox or Firefox ESR to protect their systems.
Technical details
An integer overflow vulnerability exists within the 'Widget: Win32' component of Mozilla Firefox. The flaw is triggered when the browser processes specific inputs or events on Windows systems, leading to an arithmetic overflow during memory allocation or buffer sizing. While specific exploitation details are restricted in the associated bug report, such overflows in browser widgets typically allow for memory corruption, which could potentially be leveraged for a sandbox escape or remote code execution. The vulnerability is addressed in Firefox 151 and Firefox ESR 140.11.
Affected products
- Mozilla Firefox < 151
- Mozilla Firefox ESR < 140.11
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-05-19: patched