Description
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Memory safety bugs, identified as CWE‑119 buffer‑overflow weaknesses, were discovered in Mozilla Firefox version 152.0.3. These bugs caused memory corruption, and the effort they could be leveraged to execute arbitrary code within the browser process.

Affected Systems

The vulnerability affects Mozilla’s Firefox browser, specifically version 152.0.3. The vendor released a fix in 152.0.4, and all later releases contain the remediation.

Risk and Exploitability

The CVSS score of 7.5 signals a medium‑to‑high severity. EPSS is < 1 % and the issue is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. No publicly available exploit has been disclosed. Based on the description, trigger the memory corruption; however, the precise attack path is not detailed in the advisory.

Generated by OpenCVE AI on July 17, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 152.0.4 or later to patch the identified CWE‑119 buffer‑overflow bugs
  • Configure Firefox to run all content in a sandboxed environment to mitigate the impact of any remaining buffer overflows (CWE‑119)
  • If the patch cannot be applied immediately, disable or restrict extensions to reduce injection vectors that could exploit the buffer‑overflow weakness (CWE‑119)

Generated by OpenCVE AI on July 17, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-416
CWE-787

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 30 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-416
CWE-787

Tue, 30 Jun 2026 14:00:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
Title Memory safety bugs fixed in Firefox 152.0.4
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-06T14:35:48.546Z

Reserved: 2026-06-30T13:32:01.763Z

Link: CVE-2026-14241

cve-icon Vulnrichment

Updated: 2026-06-30T14:09:19.427Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:30:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer