CVE-2026-12316 Details
Description
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
A mitigation bypass vulnerability has been identified in the DOM: Security component of Mozilla Firefox. This vulnerability allows for the circumvention of security measures that were previously implemented. It affects Firefox versions prior to 152.
Users can upgrade to Firefox 152 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=2045496 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2026-57/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2026-60/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 152.0.0 |
CPE
Remediation
| |
| mozilla thunderbird | < 152.0.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | New CVE Received | [email protected] |