MEDIUM 6.5

CVE-2026-12325: Firefox & Thunderbird Image Processing DoS Vulnerability

A denial-of-service vulnerability exists in Firefox and Thunderbird's image processing component. An attacker can craft a malicious image that, when viewed by a user, causes the application to crash or become unresponsive. The vulnerability requires user interaction—specifically, the user must open or view the malicious image—but no special privileges are needed. This is a localized impact issue affecting availability rather than data confidentiality or integrity.

Source data · NVD / CISA · public domain

CVSS
3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-400
Affected products
4 configuration(s)
Published / Modified
2026-06-16 / 2026-06-17

NVD description (verbatim)

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

6 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-12325 is a denial-of-service flaw in the ImageLib graphics component affecting Mozilla Firefox and Thunderbird. The vulnerability stems from improper handling of specially crafted image data, classified under CWE-400 (Uncontrolled Resource Consumption). The attack vector is network-based with low complexity; the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) reflects that user interaction is required to trigger the denial of service, but once triggered, availability is severely impacted. No authentication or privileges are required from the attacker's perspective.

Business impact

End users and organizations relying on Firefox or Thunderbird for email and web browsing face service disruption risk. A malicious image delivered via email attachment, web link, or embedded in a webpage could crash the user's email client or browser, disrupting work and potentially affecting business continuity. For organizations with centralized browser or email deployment, widespread exposure is possible if malicious images are shared across the user base. However, the impact is limited to denial of service; no data theft or system compromise occurs.

Affected systems

Mozilla Firefox (prior to version 152), Firefox ESR (prior to versions 140.12 and 115.37), Mozilla Thunderbird (prior to version 152), and Thunderbird (prior to version 140.12) are affected. Organizations using older Firefox or Thunderbird releases, including Extended Support Release versions, should verify their installed versions against these fixed versions.

Exploitability

The vulnerability has not been added to the CISA KEV catalog, indicating no evidence of active exploitation in the wild at the time of publication. However, exploitability is moderate: an attacker need only craft a malicious image and serve it via network channels—email, web, or messaging. User interaction is required, but social engineering to open an image attachment or click a link is commonplace. The technical barrier to exploitation is low; the primary constraint is user action.

Remediation

Users and administrators should update Firefox to version 152 or later, Firefox ESR to version 140.12 (or version 115.37 if on the 115.x ESR track), Thunderbird to version 152, or Thunderbird to version 140.12, depending on the product and version in use. Verify against vendor advisories to confirm patch version numbers and compatibility before deployment. No workarounds are documented; patching is the primary remediation path.

Patch guidance

Prioritize patching within 30 days for general users and 14 days for critical business environments. Firefox and Thunderbird typically auto-update by default; verify auto-update is enabled in settings (Help > About Firefox or Thunderbird). For managed deployments, push updates via your endpoint management tools or Mozilla's centralized update mechanisms. Test patches in a non-production environment first, particularly for ESR versions, to ensure no compatibility regressions with organizational extensions or workflows.

Detection guidance

Monitor for unusual crashes or unresponsiveness in Firefox and Thunderbird instances, particularly when image-heavy emails or web pages are accessed. Web proxies and email gateways can log image file types and sources to identify potential malicious image delivery. Endpoint detection and response (EDR) tools may flag repeated application crashes tied to image processing. Consider implementing block-level image-type restrictions in email gateways for uncommon or suspicious image formats if organizational policy permits.

Why prioritize this

This vulnerability warrants prompt but not emergency patching. The CVSS 6.5 MEDIUM score reflects limited scope (availability only) and mandatory user interaction. Absence from the KEV catalog suggests no active exploitation. However, the ubiquity of Firefox and Thunderbird, the ease of image-based attack delivery, and the potential for widespread user disruption justify elevated priority in patch schedules. Organizations should treat this as a high-priority update within the normal patch cycle rather than an out-of-band emergency.

Risk score, explained

CVSS 3.1 score of 6.5 (MEDIUM) reflects: network attack vector with low complexity, no authentication required, but mandatory user interaction. The impact is high for availability (A:H) but none for confidentiality or integrity. The attack is unscoped—confined to the affected application. This balances exploitability (network-based, low barrier) against limited damage scope (denial of service only, no data exfiltration or privilege escalation). The score appropriately reflects a disruptive but contained risk.

Frequently asked questions

Can this vulnerability steal my passwords or data?

No. This is a denial-of-service vulnerability affecting only availability. It cannot exfiltrate data, steal credentials, or modify files. The attacker's goal is to crash or hang your email or browser application, not to access your information.

Do I need to be running Firefox or Thunderbird to be at risk?

Yes, this vulnerability is specific to Mozilla Firefox and Thunderbird. Other browsers or email clients are not affected. Users of Chrome, Safari, Outlook, or other applications are not vulnerable to this particular issue.

What should I do if I encounter a malicious image before patching?

Avoid opening image attachments from unknown senders, especially unusual file types. If you accidentally open a malicious image and your application crashes, simply reopen it—no data has been compromised. Apply the relevant patch as soon as possible to prevent future incidents.

Is this vulnerability currently being exploited?

There is no public evidence of active exploitation (the vulnerability is not on CISA's KEV list). However, the attack is simple to execute, so remaining unpatched increases your risk over time. Prioritize patching within your standard update cycle.

This analysis is provided for informational purposes and reflects publicly available information as of the publication date. Patch version numbers and compatibility details should be verified against official Mozilla security advisories before deployment. SEC.co makes no warranty regarding the completeness or accuracy of vendor-provided patch information. Organizations should conduct their own testing and risk assessment before applying patches to production environments. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).