CVE-2026-12306: Mozilla Firefox & Thunderbird Memory Safety Vulnerability – Patch Now
A memory safety vulnerability was discovered in Firefox and Thunderbird that could allow attackers to read sensitive information from affected systems. The flaw affects the way these applications handle memory, creating a situation where an attacker could potentially access data they shouldn't be able to reach. Mozilla has addressed this issue in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weaknesses (CWE)
- CWE-119
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-06-16 / 2026-06-18
NVD description (verbatim)
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
This vulnerability is a memory safety bug classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The issue requires no user interaction and no privileges to exploit, as indicated by the CVSS vector. It results in a confidentiality impact—an attacker can read sensitive data—but does not enable code execution or system availability attacks. The vulnerability affects Mozilla's browser and email client across multiple product lines and update branches.
Business impact
Organizations relying on Firefox or Thunderbird face a limited but real risk of data exposure. The confidentiality impact means that sensitive information accessible to the application process could be leaked to an attacker on the network. For enterprises using Thunderbird for email communication, this could expose message content or credentials. For Firefox users, session data, cookies, or cached sensitive information could be at risk. The CVSS score of 5.3 reflects a moderate severity that warrants timely patching but is not critical.
Affected systems
This vulnerability affects Mozilla Firefox (all versions prior to 152), Mozilla Firefox ESR (versions prior to 140.12), Mozilla Thunderbird (all versions prior to 152), and Mozilla Thunderbird ESR (versions prior to 140.12). Both consumer and enterprise-supported release branches are impacted. Organizations running older versions of either product should prioritize inventory and upgrade planning.
Exploitability
The vulnerability is exploitable over the network without requiring user interaction or any form of authentication. An attacker positioned on the network path (or controlling network infrastructure) could potentially trigger the memory safety flaw and read data from the process. However, the attack does not appear to be trivial—it requires triggering a specific memory condition. This vulnerability is not currently tracked on the CISA Known Exploited Vulnerabilities (KEV) catalog, suggesting limited real-world weaponization at this time, though organizations should not rely on this as a reason to delay patching.
Remediation
Organizations should update Firefox to version 152 or later, Firefox ESR to version 140.12 or later, Thunderbird to version 152 or later, and Thunderbird ESR to version 140.12 or later. Mozilla typically delivers security updates automatically for desktop browsers, but verification after restart is recommended. Thunderbird updates may require manual intervention depending on deployment configuration. Enterprise environments should validate patches in testing environments before broad rollout to ensure application compatibility.
Patch guidance
Apply patches according to your organization's change management policy. For Firefox, enable automatic updates or use your organization's software deployment tools to push version 152 or later. For Firefox ESR users in enterprise environments, coordinate with Mozilla's ESR schedule and deploy version 140.12 or later. Thunderbird users should similarly upgrade to version 152 or 140.12 ESR. Verify successful patching by checking Help > About in Firefox/Thunderbird to confirm the running version matches the target. Organizations using centralized browser/email management should test patches in a pilot group before full deployment.
Detection guidance
Monitor for successful exploitation by reviewing network logs for suspicious data exfiltration patterns from systems running unpatched Firefox or Thunderbird. Application crash logs and OS-level memory protection warnings may also signal exploitation attempts. Consider implementing outbound data loss prevention (DLP) rules specific to Firefox and Thunderbird processes to catch anomalous data flows. Additionally, maintain an inventory of deployed versions and compare against the patched versions listed in the source advisory to identify at-risk systems. Endpoint detection and response (EDR) tools should flag memory safety violations if configured to monitor process behavior.
Why prioritize this
While this vulnerability has a CVSS score of 5.3 (Medium), it deserves prompt attention because: (1) Firefox and Thunderbird are widespread in both consumer and enterprise environments, (2) the attack requires no user interaction or authentication, (3) the confidentiality impact could expose sensitive corporate communications or user data, and (4) patches are readily available. The absence from the KEV catalog suggests lower immediate threat, but organizations should not delay—prioritize according to your risk tolerance and data sensitivity, with enterprise email (Thunderbird) environments receiving first priority.
Risk score, explained
The CVSS 3.1 score of 5.3 reflects a network-exploitable memory safety issue with no user interaction required and no authentication needed. However, the impact is limited to confidentiality (data read), with no integrity or availability consequences. The vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) captures a realistic but not catastrophic attack scenario. The Medium severity designation is appropriate—this is not a remote code execution or denial-of-service vulnerability, but it does enable data leakage and should be patched in a timely manner.
Frequently asked questions
Do I need to restart my system after updating Firefox or Thunderbird to patch this vulnerability?
Firefox typically requires a browser restart to apply the update, though many users may not need to restart their entire system. Thunderbird similarly requires an application restart. Mozilla often prompts users to restart the application after download, or you can manually close and reopen the application to complete the update process.
Is this vulnerability being actively exploited in the wild?
This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog, which means there is no publicly reported active exploitation at the time of disclosure. However, the absence from this list does not guarantee no exploitation is occurring—it reflects reported incidents. Organizations should still patch promptly.
What is the difference between Firefox ESR and standard Firefox for patching purposes?
Firefox ESR (Extended Support Release) is designed for organizations that need a slower update cycle and longer support periods. Security patches for ESR versions are released on a different schedule than standard Firefox. Verify whether your organization uses standard Firefox (version 152) or ESR (version 140.12) and apply the corresponding patch.
Could this vulnerability expose my email or browsing passwords?
This vulnerability affects memory safety and could expose data resident in the application's memory, which could include cached credentials or session tokens. For Thunderbird users, this could theoretically include email content and authentication data. For Firefox users, session cookies and stored credentials could be at risk. This reinforces the importance of prompt patching and the use of password managers with strong master passwords.
This analysis is provided for informational purposes and reflects the vulnerability details available as of the publication date. The CVSS score, affected versions, and patch information are derived from official Mozilla security advisories and NIST records. Organizations should verify patch availability and compatibility against their specific deployment configurations before applying updates. This vulnerability assessment does not constitute a guarantee of security and should be considered part of a comprehensive risk management program. For the most current patch status and technical details, consult the official Mozilla Security Advisory and your vendor's recommendations. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-12300MEDIUMFirefox and Thunderbird Memory Safety Vulnerability (CVSS 5.3)
- CVE-2026-12301MEDIUMFirefox & Thunderbird Memory Safety Vulnerability
- CVE-2026-12307MEDIUMMemory Safety Vulnerability in Firefox & Thunderbird – What You Need to Know
- CVE-2026-12308MEDIUMFirefox & Thunderbird Memory Safety Vulnerability – MEDIUM Severity Patch Available
- CVE-2026-12309MEDIUMMozilla Firefox and Thunderbird Memory Safety Vulnerability (CVSS 6.5)
- CVE-2026-12329MEDIUMMozilla Firefox and Thunderbird Memory Safety Vulnerability (CVSS 5.3)
- CVE-2026-12330MEDIUMFirefox & Thunderbird Internationalization Boundary Condition Flaw
- CVE-2026-10701HIGHFirefox Text Rendering Memory Disclosure Vulnerability