Mozilla Firefox 125 Critical Flaws Allow Remote Code Execution
Key Takeaways Mozilla has released Firefox version 152 to patch numerous high-severity vulnerabilities. These flaws could lead to remote code execution (RCE), privilege escalation, and sandbox...
Key Takeaways
- Mozilla has released Firefox version 152 to patch numerous high-severity vulnerabilities.
- These flaws could lead to remote code execution (RCE), privilege escalation, and sandbox escapes.
- Affected products include Firefox, Firefox ESR, and Thunderbird.
- Immediate updates are critical to prevent potential system compromise.
Mozilla has rolled out Firefox 152, a crucial update designed to rectify a series of high-severity vulnerabilities. These critical flaws could enable attackers to execute arbitrary code remotely and bypass browser security measures, posing significant risks to user systems.
The security advisory, issued on June 16, 2026, details a broad spectrum of vulnerabilities impacting fundamental browser components. The urgency for users to update their installations without delay has been strongly emphasized.
Among the patched issues, several are categorized as high-impact, predominantly concerning memory safety defects, use-after-free conditions, and privilege escalation vulnerabilities. Attackers could exploit these weaknesses by enticing users to interact with specially crafted web content, potentially leading to the execution of malicious code on compromised machines.
Critical Vulnerabilities Addressed in Firefox 152
The update specifically targets several high-risk vulnerabilities, including:
- CVE-2026-12289: A privilege escalation flaw within the WebRender component that could grant attackers elevated access rights.
- CVE-2026-12291: A use-after-free vulnerability affecting the HTTP networking component, which could result in memory corruption.
- CVE-2026-12293: Another use-after-free issue, this time in the WebGPU component, exploitable for code execution.
- CVE-2026-12294 to CVE-2026-12297: A set of sandbox escape vulnerabilities impacting critical mechanisms such as DOM Workers, Navigation, and process sandboxing.
- CVE-2026-12299: A JIT miscompilation bug in the DOM and HTML components, potentially leading to unpredictable execution behavior.
Mozilla also reported fixing several memory safety bugs, including CVE-2026-12290, CVE-2026-12298, CVE-2026-12326, and CVE-2026-12328, all of which could lead to memory corruption. These types of flaws are particularly dangerous as they often serve as prerequisites for remote code execution. The presence of multiple sandbox escape vulnerabilities further broadens the potential attack surface, allowing attackers to break out of the browser’s confined environment.
A common attack scenario involves an attacker first exploiting a memory corruption vulnerability to achieve code execution within the browser’s sandbox. Subsequently, a sandbox escape flaw is used to bypass these security boundaries, ultimately compromising the underlying operating system. For instance, chaining CVE-2026-12291 (a use-after-free) with CVE-2026-12294 (a DOM Workers sandbox escape) could enable a full browser-to-system compromise.
Beyond the critical issues, Mozilla also addressed various moderate and low-severity vulnerabilities. These include a same-origin policy bypass (CVE-2026-12304) related to cookie handling, information disclosure vulnerabilities in the WebGPU and Password Manager components, and several mitigation bypasses in DOM security mechanisms. Additionally, denial-of-service (DoS) issues in media playback and graphics components, alongside numerous other memory safety bugs, were patched. While less severe individually, these flaws could still be combined with other vulnerabilities to enhance attack efficacy.
According to advisory MFSA 2026-57, these vulnerabilities have been patched across Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 152. Older versions remain susceptible to these attacks.
What You Should Do
- Update Immediately: Users and organizations should update Firefox to version 152 or later without delay.
- Apply ESR Updates: Ensure Firefox ESR installations are updated to the latest versions (140.12 or 115.37).
- Enable Automatic Updates: Configure browsers to automatically apply security updates to stay protected.
- Monitor Systems: Remain vigilant for any signs of suspicious browser activity or attempts to exploit these vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.