Mozilla Product Security Update Advisory
Overview
Security updates addressing vulnerabilities in Mozilla products have been released. The affected products are Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR; users should update to the latest version.
Affected Products and Versions
- Firefox versions prior to 152.
- Firefox ESR versions earlier than 140.12.
- Firefox ESR versions earlier than 115.37.
- Thunderbird versions earlier than 152.
- Thunderbird ESR versions earlier than 140.12.
Resolved Vulnerabilities
- Graphics: CVE-2026-12289, a privilege escalation vulnerability in the WebRender component.
- CVE-2026-12290, a memory safety vulnerability affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR.
- Networking: CVE-2026-12291, a use-after-free vulnerability in the HTTP component.
- CVE-2026-12292, a boundary condition error vulnerability in the Web Audio component.
- Graphics: A use-after-free vulnerability in the WebGPU component (CVE-2026-12293).
- DOM: A sandbox escape vulnerability in the Workers component (CVE-2026-12294).
- DOM: A sandbox escape vulnerability in the Navigation component (CVE-2026-12295).
- Security: A sandbox escape vulnerability in the Process Sandboxing component (CVE-2026-12296).
- CVE-2026-12297, a sandbox escape vulnerability caused by a boundary condition error in the Networking component.
- CVE-2026-12326, a memory safety vulnerability affecting Firefox and Thunderbird.
- CVE-2026-12328, a memory safety vulnerability affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR.
Updated Versions
- CVE-2026-12289, CVE-2026-12290, CVE-2026-12291, CVE-2026-12294, CVE-2026-12295, CVE-2026-12297, CVE-2026-12328 has been resolved in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird ESR 140.12.
- CVE-2026-12292 and CVE-2026-12296 have been fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird ESR 140.12.
- CVE-2026-12293 and CVE-2026-12326 have been resolved in Firefox 152 and Thunderbird 152.
Note
Mozilla recommends updating to the latest version with Vulnerability Patches, as outlined on the reference site.