Description
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
Published: 2026-06-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that memory corruption bugs were disclosed in Mozilla Firefox version 152.0.3. The description indicates that developers observed evidence of memory corruption that could, with enough effort, be leveraged to execute arbitrary code. This vulnerability pertains to a memory safety weakness where an attacker could overwrite or read beyond a valid memory buffer, a classic pathway to code execution. The potential impact is full compromise of the affected system if an attacker execution of arbitrary instructions with the privileges of the browser process.

Affected Systems

Based on the description, it is inferred that the affected software is Mozilla Firefox, specifically the 152.0.3 release line. Users running this version are vulnerable until they upgrade to Firefox 152.0.4 or later, where the bugs have been resolved.

Risk and Exploitability

Based on the description, it is inferred that no published CVSS or EPSS score is available for this entry, and the vulnerability is not listed in the CISA KEV catalog. However, the description acknowledges that with sufficient effort the memory corruption could lead to arbitrary code execution, implying a high severity in principle. The lack of a publicly known exploitation vector or active exploits does not diminish the risk, historically a fertile ground for attackers. The attacker would need to supply specially crafted input or manipulate the web page rendering pipeline to trigger the corruption, so higher‑level application or user interaction is required.

Generated by OpenCVE AI on June 30, 2026 at 16:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 152.0.4 or later on all affected systems.
  • Enforce that the patched browser is the only version deployed in the environment via administrative policy.
  • If updating is not immediately possible, restrict access to untrusted web content and monitor for signs of exploitation.

Generated by OpenCVE AI on June 30, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 30 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-416
CWE-787

Tue, 30 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
Title Memory safety bugs fixed in Firefox 152.0.4
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-06-30T13:32:01.957Z

Reserved: 2026-06-30T13:32:01.763Z

Link: CVE-2026-14241

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-30T16:15:06Z

Weaknesses