Memory Safety Vulnerability in Firefox from Mozilla
CVE-2026-12298

5.4MEDIUM

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-12298?

A memory safety vulnerability was identified and addressed in Mozilla's Firefox version 152 and Firefox ESR 140.12. This flaw could potentially allow attackers to exploit the memory management in the browser, leading to various security issues. Regular updates are crucial to ensure that users are protected from such vulnerabilities. It is recommended to upgrade to the latest version of Firefox or ESR to maintain optimal security.

Affected Version(s)

Firefox 140.12

Firefox 152

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haruka Yamazaki
.