Mitigation Bypass in Firefox Security Component
CVE-2026-12315

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-12315?

A vulnerability exists in the security component of Firefox that allows attackers to bypass mitigation measures intended to protect the browser's DOM (Document Object Model). This issue affects multiple versions of Firefox, including Firefox 152 and earlier, as well as Firefox Extended Support Release (ESR) 140.11 and earlier. Users are encouraged to update to Firefox 152 or Firefox ESR 140.12, where the vulnerability has been addressed. Detailed information about this vulnerability can be found in Mozilla's security advisories.

Affected Version(s)

Firefox 140.12

Firefox 152

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Minh
.