Executive brief
Mozilla Firefox is a widely used web browser. Multiple memory safety vulnerabilities were identified that could allow an attacker to corrupt the browser's memory. In a worst-case scenario, this could allow an attacker to take control of a user's computer or execute unauthorized software simply by having the user visit a malicious website.
Technical details
This advisory covers a collection of memory safety bugs identified through internal testing and fuzzing. The vulnerabilities manifest as memory corruption within the browser engine. While specific root causes for each bug are not detailed, Mozilla acknowledges that these flaws could be leveraged for arbitrary code execution given sufficient exploit development effort. The attack vector is typically remote, requiring a user to navigate to a specially crafted web page (UI interaction). These issues were addressed by improving memory handling and safety checks in the browser's codebase. Users should update to Firefox 151 to mitigate these risks.
Affected products
- Mozilla Firefox 150
Timeline
- 2026-05-19: disclosed
- 2026-05-19: patched
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1362365%2C1860538%2C1929005%2C1983353%2C1998526%2C2023271%2C2023943%2C2024244%2C2024260%2C2024443%2C2024665%2C2024774%2C2024916%2C2025346%2C2025357%2C2025406%2C2025434%2C2025488%2C2025496%2C2025942%2C2025947%2C2025968%2C2026279%2C2027159%2C2027239%2C2027276%2C2027308%2C2027310%2C2027324%2C2027329%2C2027363%2C2027381%2C2027382%2C2027383%2C2028274%2C2028884%2C2029060%2C2029065%2C2029068%2C2029281%2C2029293%2C2029297%2C2029303%2C2029439%2C2029448%2C2029703%2C2029720%2C2029721%2C2029723%2C2029770%2C2029771%2C2029782%2C2029818%2C2029885%2C2030100%2C2030379%2C2030385%2C2030979%2C2031119%2C2031122%2C2034119%2C2034791%2C2035209%2C2036666%2C2037986
- https://www.mozilla.org/security/advisories/mfsa2026-46/