CVE-2026-12305: Firefox & Thunderbird Memory Safety Vulnerability (CVSS 7.5)
A memory safety vulnerability was discovered in Firefox and Thunderbird that could allow an attacker to crash the application or potentially cause other harmful effects through network access. The flaw affects the way these programs manage memory, and no user interaction is required for exploitation. Mozilla has patched this issue in recent versions of both applications.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-119
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-06-16 / 2026-06-18
NVD description (verbatim)
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12305 is a memory safety bug (CWE-119) discovered in Mozilla Firefox and Thunderbird. The vulnerability has a CVSS 3.1 score of 7.5 (High severity) with a network attack vector, low attack complexity, and no privilege or user interaction required. The primary impact is availability—an attacker can remotely trigger an application crash or denial-of-service condition. The vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H indicates confidentiality and integrity are not compromised, but availability is severely affected.
Business impact
For organizations relying on Firefox or Thunderbird as standard endpoints, this vulnerability poses a denial-of-service risk. Widespread exploitation could disrupt employee productivity and email communications. The lack of user interaction required means attackers can trigger crashes through malicious network content (embedded in web pages or email messages), potentially affecting entire user populations. The vulnerability is not known to enable data theft or system compromise, but repeated crashes could be leveraged in social engineering or combined with other attacks.
Affected systems
Mozilla Firefox versions prior to 152, Firefox ESR versions prior to 140.12, Thunderbird versions prior to 152, and Thunderbird versions prior to 140.12 are affected. Organizations running outdated versions of these applications should prioritize updates. Extended Support Release (ESR) versions are commonly deployed in enterprise environments and require explicit attention.
Exploitability
The vulnerability is remotely exploitable over a network without requiring user interaction or elevated privileges. An attacker could craft malicious web content or email attachments designed to trigger the memory safety flaw, causing immediate application crashes. The low attack complexity and broad attack surface (any webpage or email message) make this relatively straightforward to weaponize. However, the lack of a known public exploit or inclusion in the CISA KEV catalog suggests active in-the-wild exploitation is not yet documented as widespread.
Remediation
Update Firefox to version 152 or later, Firefox ESR to version 140.12 or later, Thunderbird to version 152 or later, and Thunderbird ESR to version 140.12 or later. Organizations should prioritize ESR deployments in managed environments. Test patches in a representative environment before wide-scale rollout to ensure compatibility with existing workflows and extensions.
Patch guidance
Mozilla has released security updates addressing this vulnerability. Firefox and Thunderbird users should enable automatic updates or manually check Help > About [Firefox/Thunderbird] to trigger immediate patching. Enterprise administrators managing Firefox or Thunderbird via group policy or mobile device management should push version 152 (or 140.12 for ESR variants) to all endpoints. Verify patch installation by confirming the updated version number in the About dialog. Organizations should complete patching within 7–14 days of release to minimize exposure.
Detection guidance
Monitor for unexpected Firefox and Thunderbird process crashes in your environment using endpoint detection and response (EDR) tools or SIEM log aggregation. Web proxies and email gateways can flag suspicious content that may be crafted to exploit memory safety issues. Review browser and email logs for repeated crash events correlated with specific malicious websites or senders. Consider deploying browser isolation or sandboxing technologies for high-risk users to limit the blast radius if exploitation occurs.
Why prioritize this
This vulnerability scores 7.5 (High) due to its remote, unauthenticated attack surface and guaranteed availability impact. Although not yet in the CISA Known Exploited Vulnerabilities catalog, the ease of exploitation and presence in widely deployed consumer and enterprise applications warrants rapid patching. Organizations should treat this as a priority update within their normal security cadence.
Risk score, explained
The CVSS 3.1 score of 7.5 reflects a High-severity vulnerability with the following factors: Network-based attack vector (AV:N) allows remote exploitation, low attack complexity (AC:L) means no special conditions are needed, no privileges (PR:N) or user interaction (UI:N) are required, and confidentiality/integrity remain unaffected (C:N/I:N). The High availability impact (A:H) drives the elevated score because attackers can reliably crash the application. This score does not account for the likelihood of active exploitation, which remains undocumented in public threat intelligence.
Frequently asked questions
Does this vulnerability allow hackers to steal my data?
No. The vulnerability only affects availability—it crashes the browser or email client. There is no evidence of data theft, code execution, or system compromise from this flaw. However, repeated crashes could be part of a larger social engineering campaign.
Do I need to patch if I don't use Firefox or Thunderbird?
No, this vulnerability is specific to Mozilla Firefox and Thunderbird. Other browsers and email clients are not affected. However, if you run either of these applications in your environment, patching is recommended.
Is there an active exploit in the wild?
As of the published date, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and there is no confirmed public exploit. That said, the vulnerability is straightforward to exploit remotely, so organizations should not delay patching.
Can I work around this without updating?
The only reliable mitigation is to update to the patched versions. Organizations concerned about patch stability can deploy to a pilot group first. Consider browser isolation or sandboxing for high-risk users as a temporary supplemental control while patches are rolled out.
This analysis is based on publicly available information as of the vulnerability's publication date (2026-06-16). Exploit details and active exploitation status may change. Organizations should verify patch availability and compatibility with their specific configurations before deployment. SEC.co makes no warranty regarding the completeness or accuracy of this intelligence and recommends consulting official Mozilla security advisories and your own risk management processes for final patching decisions. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10701HIGHFirefox Text Rendering Memory Disclosure Vulnerability
- CVE-2026-12290HIGHFirefox and Thunderbird Memory Safety Vulnerability – Patch Guidance
- CVE-2026-12292HIGHFirefox and Thunderbird Web Audio Boundary Condition Vulnerability (CVSS 8.1)
- CVE-2026-12310HIGHFirefox and Thunderbird Memory Safety Vulnerability (CVSS 7.5)
- CVE-2026-12312HIGHMozilla Firefox & Thunderbird Memory Safety Vulnerability – Remote Information Disclosure
- CVE-2026-12314HIGHFirefox & Thunderbird Memory Safety Vulnerability – Patch Now
- CVE-2026-12317HIGHFirefox and Thunderbird Memory Safety Flaw (CVSS 7.5)
- CVE-2026-12318HIGHHigh-Severity Boundary Condition Flaw in NSS Libraries Affecting Firefox and Thunderbird