Mozilla Product Security Update Advisory

Mozilla Product Security Update Advisory

Overview

Security updates addressing vulnerabilities in Mozilla products have been released. The affected products are Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR; users should update to the latest version.

Affected Products and Versions

  • Firefox versions prior to 152.
  • Firefox ESR versions earlier than 140.12.
  • Firefox ESR versions earlier than 115.37.
  • Thunderbird versions earlier than 152.
  • Thunderbird ESR versions earlier than 140.12.

Resolved Vulnerabilities

  • Graphics: CVE-2026-12289, a privilege escalation vulnerability in the WebRender component.
  • CVE-2026-12290, a memory safety vulnerability affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR.
  • Networking: CVE-2026-12291, a use-after-free vulnerability in the HTTP component.
  • CVE-2026-12292, a boundary condition error vulnerability in the Web Audio component.
  • Graphics: A use-after-free vulnerability in the WebGPU component (CVE-2026-12293).
  • DOM: A sandbox escape vulnerability in the Workers component (CVE-2026-12294).
  • DOM: A sandbox escape vulnerability in the Navigation component (CVE-2026-12295).
  • Security: A sandbox escape vulnerability in the Process Sandboxing component (CVE-2026-12296).
  • CVE-2026-12297, a sandbox escape vulnerability caused by a boundary condition error in the Networking component.
  • CVE-2026-12326, a memory safety vulnerability affecting Firefox and Thunderbird.
  • CVE-2026-12328, a memory safety vulnerability affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR.

Updated Versions

  • CVE-2026-12289, CVE-2026-12290, CVE-2026-12291, CVE-2026-12294, CVE-2026-12295, CVE-2026-12297, CVE-2026-12328 has been resolved in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird ESR 140.12.
  • CVE-2026-12292 and CVE-2026-12296 have been fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird ESR 140.12.
  • CVE-2026-12293 and CVE-2026-12326 have been resolved in Firefox 152 and Thunderbird 152.

Note

Mozilla recommends updating to the latest version with Vulnerability Patches, as outlined on the reference site.