Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-16412: Firefox Memory Corruption Bug Fixed in Firefox ESR 140.13 and Firefox 153
CVE-2026-16412
CVE-2026-16412
Summary
A bug in Firefox's memory handling could allow hackers to run unauthorized code on your system. This issue affects Firefox versions 152 and 140.12. To fix the issue, update to Firefox version 153 or Firefox ESR 140.13.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | All versions |
Original title
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploi...
Original description
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Vulnerability type
CWE-119
Buffer Overflow
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2005113%2C2025369%2C2026301%2C20...
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2043035%2C2045057%2C2045187%2C20...
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045413%2C2053635%2C2053637
- https://www.mozilla.org/security/advisories/mfsa2026-68/
- https://www.mozilla.org/security/advisories/mfsa2026-70/
Published: 21 Jul 2026 · Updated: 22 Jul 2026 · First seen: 21 Jul 2026