Mozilla Foundation Security Advisory 2026-57

Security Vulnerabilities fixed in Firefox 152

Announced
June 16, 2026
Impact
high
Products
Firefox
Fixed in
  • Firefox 152

#CVE-2026-12289: Privilege escalation in the Graphics: WebRender component

Reporter
choeseyeong
Impact
high
References

#CVE-2026-12290: Memory safety bug fixed in Firefox 152

Reporter
jayjayjazz
Impact
high
References

#CVE-2026-12291: Use-after-free in the Networking: HTTP component

Reporter
Zijie Zhao
Impact
high
References

#CVE-2026-12292: Incorrect boundary conditions in the Web Audio component

Reporter
Zijie Zhao
Impact
high
References

#CVE-2026-12293: Use-after-free in the Graphics: WebGPU component

Reporter
superhei
Impact
high
References

#CVE-2026-12294: Sandbox escape in the DOM: Workers component

Reporter
Quy Pham
Impact
high
References

#CVE-2026-12295: Sandbox escape in the DOM: Navigation component

Reporter
Yaqoub Aldurayhim
Impact
high
References

#CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component

Reporter
Yaqoub Aldurayhim
Impact
high
References

#CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component

Reporter
zx
Impact
high
References

#CVE-2026-12298: Memory safety bug fixed in Firefox 152

Reporter
Haruka Yamazaki
Impact
high
References

#CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component

Reporter
Hyeonjun Ahn
Impact
high
References

#CVE-2026-12300: Memory safety bug fixed in Firefox 152

Reporter
Niklas
Impact
moderate
References

#CVE-2026-12301: Memory safety bug fixed in Firefox 152

Reporter
Richard Belisle
Impact
moderate
References

#CVE-2026-12302: Mitigation bypass in the DOM: Security component

Reporter
lebr0nli
Impact
moderate
References

#CVE-2026-12303: Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component

Reporter
Michal Andryskowski
Impact
moderate
References

#CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component

Reporter
Yaqoub Aldurayhim
Impact
moderate
References

#CVE-2026-12305: Memory safety bug fixed in Firefox 152

Reporter
Zijie Zhao
Impact
moderate
References

#CVE-2026-12306: Memory safety bug fixed in Firefox 152

Reporter
Mihalis Haatainen
Impact
moderate
References

#CVE-2026-12307: Memory safety bug fixed in Firefox 152

Reporter
Atsushi Sada
Impact
moderate
References

#CVE-2026-12308: Memory safety bug fixed in Firefox 152

Reporter
Mihalis Haatainen
Impact
moderate
References

#CVE-2026-12309: Memory safety bug fixed in Firefox 152

Reporter
Yaqoub Aldurayhim
Impact
moderate
References

#CVE-2026-12310: Memory safety bug fixed in Firefox 152

Reporter
Carl Pearson
Impact
moderate
References

#CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component

Reporter
Yaqoub Aldurayhim
Impact
moderate
References

#CVE-2026-12312: Memory safety bug fixed in Firefox 152

Reporter
Rintaro Kawasugi
Impact
moderate
References

#CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component

Reporter
evyatar
Impact
moderate
References

#CVE-2026-12314: Memory safety bug fixed in Firefox 152

Reporter
satyamasd
Impact
moderate
References

#CVE-2026-12315: Mitigation bypass in the DOM: Security component

Reporter
Nguyen Minh
Impact
moderate
References

#CVE-2026-12316: Mitigation bypass in the DOM: Security component

Reporter
Frederik Braun
Impact
moderate
References

#CVE-2026-12317: Memory safety bug fixed in Firefox 152

Reporter
Frédéric Wang Nélar
Impact
low
References

#CVE-2026-12318: Incorrect boundary conditions in the Libraries component in NSS

Reporter
Haruto Kimura
Impact
low
References

#CVE-2026-12319: Denial-of-service in the Audio/Video: Playback component

Reporter
jmwebdevelopement
Impact
low
References

#CVE-2026-12320: Information disclosure in the Password Manager component

Reporter
Av0id
Impact
low
References

#CVE-2026-12321: JIT miscompilation in the JavaScript: WebAssembly component

Reporter
JunYoung Park
Impact
low
References

#CVE-2026-12322: Clickjacking issue in the Widget: Gtk component

Reporter
Jivk
Impact
low
References

#CVE-2026-12323: Spoofing issue in the DOM: Core & HTML component

Reporter
Jody Ritonga
Impact
low
References

#CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component

Reporter
Mihalis Haatainen
Impact
low
References

#CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component

Reporter
Securin
Impact
low
References

#CVE-2026-12326: Memory safety bugs fixed in Firefox 152 and Thunderbird 152

Reporter
Ashley Zebrowski, Christian Holler, Dan Baker, Jan de Mooij, Jon Coppeard, Maurice Dauer, Nicolas B. Pierron, Nika Layzell, Randell Jesup, Rob Wu, Ryan Hunt, Steve Fink, Tom Schuster, Tomoya Nakanishi, Yannis Juglaret, Serge Guelton and the Mozilla Fuzzing Team
Impact
high
Description

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

References

#CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152

Reporter
Christian Holler, Jens Stutte, Nika Layzell, Randell Jesup, Tom Schuster and the Mozilla Fuzzing Team
Impact
moderate
Description

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

References

#CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152

Reporter
Andrew McCreight, Randell Jesup, Tom Ritter and the Mozilla Fuzzing Team
Impact
high
Description

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

References