CVE-2026-12325: Firefox & Thunderbird Image Processing DoS Vulnerability
A denial-of-service vulnerability exists in Firefox and Thunderbird's image processing component. An attacker can craft a malicious image that, when viewed by a user, causes the application to crash or become unresponsive. The vulnerability requires user interaction—specifically, the user must open or view the malicious image—but no special privileges are needed. This is a localized impact issue affecting availability rather than data confidentiality or integrity.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-400
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-06-16 / 2026-06-17
NVD description (verbatim)
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12325 is a denial-of-service flaw in the ImageLib graphics component affecting Mozilla Firefox and Thunderbird. The vulnerability stems from improper handling of specially crafted image data, classified under CWE-400 (Uncontrolled Resource Consumption). The attack vector is network-based with low complexity; the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) reflects that user interaction is required to trigger the denial of service, but once triggered, availability is severely impacted. No authentication or privileges are required from the attacker's perspective.
Business impact
End users and organizations relying on Firefox or Thunderbird for email and web browsing face service disruption risk. A malicious image delivered via email attachment, web link, or embedded in a webpage could crash the user's email client or browser, disrupting work and potentially affecting business continuity. For organizations with centralized browser or email deployment, widespread exposure is possible if malicious images are shared across the user base. However, the impact is limited to denial of service; no data theft or system compromise occurs.
Affected systems
Mozilla Firefox (prior to version 152), Firefox ESR (prior to versions 140.12 and 115.37), Mozilla Thunderbird (prior to version 152), and Thunderbird (prior to version 140.12) are affected. Organizations using older Firefox or Thunderbird releases, including Extended Support Release versions, should verify their installed versions against these fixed versions.
Exploitability
The vulnerability has not been added to the CISA KEV catalog, indicating no evidence of active exploitation in the wild at the time of publication. However, exploitability is moderate: an attacker need only craft a malicious image and serve it via network channels—email, web, or messaging. User interaction is required, but social engineering to open an image attachment or click a link is commonplace. The technical barrier to exploitation is low; the primary constraint is user action.
Remediation
Users and administrators should update Firefox to version 152 or later, Firefox ESR to version 140.12 (or version 115.37 if on the 115.x ESR track), Thunderbird to version 152, or Thunderbird to version 140.12, depending on the product and version in use. Verify against vendor advisories to confirm patch version numbers and compatibility before deployment. No workarounds are documented; patching is the primary remediation path.
Patch guidance
Prioritize patching within 30 days for general users and 14 days for critical business environments. Firefox and Thunderbird typically auto-update by default; verify auto-update is enabled in settings (Help > About Firefox or Thunderbird). For managed deployments, push updates via your endpoint management tools or Mozilla's centralized update mechanisms. Test patches in a non-production environment first, particularly for ESR versions, to ensure no compatibility regressions with organizational extensions or workflows.
Detection guidance
Monitor for unusual crashes or unresponsiveness in Firefox and Thunderbird instances, particularly when image-heavy emails or web pages are accessed. Web proxies and email gateways can log image file types and sources to identify potential malicious image delivery. Endpoint detection and response (EDR) tools may flag repeated application crashes tied to image processing. Consider implementing block-level image-type restrictions in email gateways for uncommon or suspicious image formats if organizational policy permits.
Why prioritize this
This vulnerability warrants prompt but not emergency patching. The CVSS 6.5 MEDIUM score reflects limited scope (availability only) and mandatory user interaction. Absence from the KEV catalog suggests no active exploitation. However, the ubiquity of Firefox and Thunderbird, the ease of image-based attack delivery, and the potential for widespread user disruption justify elevated priority in patch schedules. Organizations should treat this as a high-priority update within the normal patch cycle rather than an out-of-band emergency.
Risk score, explained
CVSS 3.1 score of 6.5 (MEDIUM) reflects: network attack vector with low complexity, no authentication required, but mandatory user interaction. The impact is high for availability (A:H) but none for confidentiality or integrity. The attack is unscoped—confined to the affected application. This balances exploitability (network-based, low barrier) against limited damage scope (denial of service only, no data exfiltration or privilege escalation). The score appropriately reflects a disruptive but contained risk.
Frequently asked questions
Can this vulnerability steal my passwords or data?
No. This is a denial-of-service vulnerability affecting only availability. It cannot exfiltrate data, steal credentials, or modify files. The attacker's goal is to crash or hang your email or browser application, not to access your information.
Do I need to be running Firefox or Thunderbird to be at risk?
Yes, this vulnerability is specific to Mozilla Firefox and Thunderbird. Other browsers or email clients are not affected. Users of Chrome, Safari, Outlook, or other applications are not vulnerable to this particular issue.
What should I do if I encounter a malicious image before patching?
Avoid opening image attachments from unknown senders, especially unusual file types. If you accidentally open a malicious image and your application crashes, simply reopen it—no data has been compromised. Apply the relevant patch as soon as possible to prevent future incidents.
Is this vulnerability currently being exploited?
There is no public evidence of active exploitation (the vulnerability is not on CISA's KEV list). However, the attack is simple to execute, so remaining unpatched increases your risk over time. Prioritize patching within your standard update cycle.
This analysis is provided for informational purposes and reflects publicly available information as of the publication date. Patch version numbers and compatibility details should be verified against official Mozilla security advisories before deployment. SEC.co makes no warranty regarding the completeness or accuracy of vendor-provided patch information. Organizations should conduct their own testing and risk assessment before applying patches to production environments. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-12319MEDIUMFirefox & Thunderbird Audio/Video DoS Vulnerability – Patch & Detection Guide
- CVE-2019-25721MEDIUMDräger Infinity M300 Denial-of-Service Vulnerability – Network-Induced Device Reboots
- CVE-2019-25724MEDIUMDräger Infinity M300 Denial-of-Service Vulnerability Impact on Patient Monitoring
- CVE-2025-48648MEDIUMAndroid NotificationManagerService Resource Exhaustion DoS
- CVE-2026-0042MEDIUMAndroid UBSan Resource Exhaustion Denial of Service
- CVE-2026-0069MEDIUMAndroid Resource Exhaustion in APK Signature Verification
- CVE-2026-0074MEDIUMAndroid LauncherProcessImageListener Denial of Service Vulnerability
- CVE-2026-10156MEDIUMOpen5GS Resource Exhaustion Vulnerability in nf-instances Endpoint