Junglewise Threat Intelligence

CVE-2026-8975: Mozilla Firefox memory safety bugs

CVE-2026-8975 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Firefox ESR are popular web browsers used to access the internet. Multiple memory safety vulnerabilities were identified that could allow an attacker to corrupt the browser's memory. If successfully exploited, these flaws could allow an attacker to take control of a user's computer or execute unauthorized commands after the user visits a malicious website.

Technical details

This advisory addresses a collection of memory safety bugs identified through internal fuzzing and security audits. The vulnerabilities exhibit evidence of memory corruption, which Mozilla developers presume could be leveraged for arbitrary code execution with sufficient effort. The attack vector is typically remote, requiring a user to navigate to a specially crafted web page. These issues affected Firefox 150, Firefox ESR 140.10, and Firefox ESR 115.35. Patches have been released in Firefox 151, Firefox ESR 140.11, and Firefox ESR 115.36.

Affected products

  • Mozilla Firefox ESR 115.35, 140.10
  • Mozilla Firefox 150

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: patched

References

Related threats