Executive brief
Mozilla has released security updates to address multiple memory safety vulnerabilities in the Firefox and Firefox ESR web browsers. These flaws could allow an attacker to corrupt the browser's memory, potentially leading to the execution of unauthorized code on a user's system. Such an exploit could result in the theft of sensitive data, unauthorized access to accounts, or the installation of malicious software if a user visits a specially crafted website.
Technical details
Mozilla developers and community members reported several memory safety bugs in Firefox 150 and Firefox ESR 140.10. These vulnerabilities encompass various memory corruption issues that, while not individually detailed, are presumed to be exploitable for arbitrary code execution given sufficient effort. The attack vector typically involves a user navigating to a malicious webpage that triggers the memory corruption. The vulnerabilities were addressed by improving memory handling and safety checks in the browser engine. Users are advised to update to Firefox 151 or Firefox ESR 140.11 to mitigate these risks.
Affected products
- Mozilla Firefox ESR 140.10
- Mozilla Firefox 150
Timeline
- 2026-05-19: advisory: Mozilla Foundation Security Advisory MFSA2026-46 and MFSA2026-48 published.
- 2026-05-19: patched: Fixed in Firefox 151 and Firefox ESR 140.11.
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1784128%2C1883230%2C1983677%2C2022390%2C2023116%2C2023657%2C2024255%2C2024418%2C2024441%2C2024447%2C2024966%2C2025412%2C2025467%2C2025940%2C2025950%2C2025956%2C2026284%2C2027247%2C2027255%2C2027288%2C2027306%2C2027322%2C2027332%2C2027333%2C2028266%2C2028292%2C2028319%2C2028526%2C2028870%2C2028876%2C2028882%2C2029062%2C2029309%2C2029414%2C2029422%2C2029428%2C2029447%2C2029732%2C2029785%2C2029793%2C2029813%2C2029899%2C2031028%2C2031457%2C2032039%2C2033610%2C2033854%2C2034498%2C2034628%2C2034978%2C2035966%2C2036668%2C2036905%2C2036930
- https://www.mozilla.org/security/advisories/mfsa2026-46/
- https://www.mozilla.org/security/advisories/mfsa2026-48/