CVE-2026-12307 Details
Description
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
A memory safety vulnerability has been identified in Mozilla Firefox. This issue affects Firefox versions 151 and prior to 152, as well as Firefox ESR 140.11 and prior to 140.12. The vulnerability arises from memory corruption, which could potentially be exploited to execute arbitrary code.
Users can upgrade to Firefox 152 or Firefox ESR 140.12 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=2038133 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2026-57/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2026-58/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2026-60/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2026-61/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 140.12.0 < 152.0.0 |
CPE
Remediation
| |
| mozilla thunderbird | < 140.12.0 < 152.0.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | New CVE Received | [email protected] |