Threat reportVulnerabilityTL-2026-0855

Multiple Vulnerabilities in Firefox 152 Enable Remote Code Execution and Sandbox Escape (MFSA 2026-57)

highPATCHED

Multiple Vulnerabilities in Firefox 152 Enable Remote Code (TL-2026-0855), also tracked as MFSA 2026-57, is a high-severity software vulnerability, first published 2026-06-18. It has no confirmed attribution, affects Mozilla Firefox, references 40 CVEs (CVE-2026-12289, CVE-2026-12290, CVE-2026-12291), maps to 18 MITRE ATT&CK techniques (T1041, T1059.007, T1068), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
40Referenced vulnerabilities
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0855

Threat ID
TL-2026-0855
Also known as
MFSA 2026-57, Firefox 152 Security Advisory
Severity
HIGH
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
all sectors, enterprise, government, financial, technology
Target regions
Global
Detection rules
9
Indicators of compromise
20

How Multiple Vulnerabilities in Firefox 152 Enable Remote Code works

Mozilla's MFSA 2026-57 advisory fixes 39 vulnerabilities in Firefox 152, including use-after-free, memory-safety/corruption, JIT miscompilation, and four distinct sandbox-escape flaws that, chained, allow remote code execution when a victim loads specially crafted web content. Fixes are also shipped in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 152.

On June 16, 2026 Mozilla published Security Advisory MFSA 2026-57, addressing 39 vulnerabilities in Firefox 152 (with parallel fixes in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 152). The advisory is dominated by classic browser memory-safety issues reachable from untrusted web content over the network attack vector, requiring only that a user visit or render a malicious page (drive-by / client-side execution).

The highest-impact issues are a use-after-free in the HTTP networking stack (CVE-2026-12291) and a use-after-free in the WebGPU graphics subsystem (CVE-2026-12293), both leading to memory corruption that can be leveraged for arbitrary code execution inside the content process. A JIT miscompilation in DOM: Core & HTML (CVE-2026-12299) produces unpredictable execution behavior that can bypass memory protections, and a WebAssembly JIT miscompilation (CVE-2026-12321) is also fixed. Multiple aggregate memory-safety roll-up bugs (CVE-2026-12290, 12298, 12326, 12328) carry High impact and are described by Mozilla as showing evidence of memory corruption that, with sufficient effort, could be exploited to run arbitrary code.

Four High-severity sandbox-escape vulnerabilities are the most strategically significant: CVE-2026-12294 (DOM: Workers), CVE-2026-12295 (DOM: Navigation), CVE-2026-12296 (Security: Process Sandboxing), and CVE-2026-12297 (incorrect boundary conditions in Networking). A real-world exploit chain pairs one of the content-process memory-corruption primitives (e.g., the HTTP or WebGPU UAF) with a sandbox escape to break out of the renderer/content sandbox and interact with the underlying operating system, and optionally CVE-2026-12289 (privilege escalation in Graphics: WebRender) to elevate privileges on the host. Additional issues include same-origin-policy bypass via cookie handling (CVE-2026-12304), DOM security mitigation bypasses (CVE-2026-12302, 12315, 12316), information disclosure paired with sandbox escape (CVE-2026-12311, 12313), WebGPU information disclosure (CVE-2026-12303), Password Manager information disclosure (CVE-2026-12320), GTK widget clickjacking (CVE-2026-12322), DOM spoofing (CVE-2026-12323), and several denial-of-service flaws in media playback (CVE-2026-12319) and graphics/ImageLib (CVE-2026-12325).

Mozilla provided no CVSS base scores in the advisory and there is no public proof-of-concept or confirmed in-the-wild exploitation reported in the source material; severity is therefore tracked using Mozilla's own High/Moderate/Low impact ratings. Given the demonstrated RCE-plus-sandbox-escape potential against one of the most widely deployed browsers, organizations should treat patch rollout to Firefox 152 / ESR 140.12 / ESR 115.37 / Thunderbird 152 as a priority.

MITRE ATT&CK techniques used in TL-2026-0855

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer

Collection

T1185 Browser Session Hijacking

Initial Access

T1189 Drive-by Compromise; T1566.002 Spearphishing Link

Defense Evasion

T1211 Exploitation for Stealth

Credential Access

T1212 Exploitation for Credential Access; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Impact

T1499 Endpoint Denial of Service; T1499.004 Application or System Exploitation

Discovery

T1518 Software Discovery

Reconnaissance

T1592.002 Software

Affected products and versions in Multiple Vulnerabilities in Firefox 152 Enable Remote Code

  • Mozilla — Firefox
    Vulnerable versions: < 152
    Fixed in: 152
  • Mozilla — Firefox ESR (140.x)
    Vulnerable versions: < 140.12
    Fixed in: 140.12
  • Mozilla — Firefox ESR (115.x)
    Vulnerable versions: < 115.37
    Fixed in: 115.37
  • Mozilla — Thunderbird
    Vulnerable versions: < 152
    Fixed in: 152

Remediation for Multiple Vulnerabilities in Firefox 152 Enable Remote Code

Patches

  • Firefox 152
  • Firefox ESR 140.12
  • Firefox ESR 115.37
  • Thunderbird 152

Immediate actions

  • Update Firefox to version 152 on all desktop endpoints immediately
  • Update Firefox ESR deployments to 140.12 (140.x branch) or 115.37 (115.x branch)
  • Update Thunderbird to version 152
  • Use enterprise management (Firefox policies.json / MSI / package managers) to force-deploy the patched build and verify the reported version

Workarounds

  • No vendor workaround; patching is the only remediation
  • Where immediate patching is impossible, restrict high-risk browsing, disable WebGPU (dom.webgpu.enabled=false) and Web Audio where unused, and consider browser isolation/RBI for untrusted sites

Longer-term hardening

  • Enforce automatic browser updates organization-wide and monitor for endpoints stuck on vulnerable versions
  • Maintain endpoint detection capable of flagging child-process spawns from firefox.exe (sandbox-escape indicators)
  • Adopt application allow-listing and OS-level exploit mitigations (CET, Win32k lockdown, ACG/CIG) to raise the cost of content-process RCE
  • Track Mozilla MFSA advisories and integrate browser version telemetry into vulnerability management

CVEs associated with Multiple Vulnerabilities in Firefox 152 Enable Remote Code

Weaknesses (CWE) in Multiple Vulnerabilities in Firefox 152 Enable Remote Code

CWE-416, CWE-787, CWE-125, CWE-119, CWE-843, CWE-693, CWE-346, CWE-200, CWE-269, CWE-400

Timeline of Multiple Vulnerabilities in Firefox 152 Enable Remote Code

  • Thunderbird 152 released incorporating the shared Gecko memory-safety fixes (CVE-2026-12326, 12327, 12328).
  • Firefox ESR 115.37 released addressing the applicable subset of MFSA 2026-57 vulnerabilities.
  • Firefox ESR 140.12 released addressing the applicable subset of MFSA 2026-57 vulnerabilities.
  • Firefox 152 released with fixes for all 39 CVEs, including four High-severity sandbox escapes and HTTP/WebGPU use-after-free RCE primitives.
  • Mozilla publishes Security Advisory MFSA 2026-57 disclosing 39 vulnerabilities fixed in Firefox 152 — 10 rated High impact, 14 Moderate and 8 Low — credited to external researchers and the Mozilla Fuzzing Team.
  • CVE identifiers CVE-2026-12289 through CVE-2026-12328 assigned to the vulnerabilities bundled in MFSA 2026-57, spanning Networking, Graphics (WebRender/WebGPU/CanvasWebGL/ImageLib), DOM (Workers/Navigation/Core&HTML/Security), Web Audio, JavaScript/WebAssembly, NSS, Password Manager and GTK widget components.
  • Blue teams build behavioral detections for browser content/GPU-process anomalies (unexpected child-process spawns, post-render outbound connections, executable writes) as no network IOCs are available for this patch-driven advisory.
  • Defenders advised to prioritize enterprise rollout of Firefox 152 / ESR 140.12 / ESR 115.37 / Thunderbird 152; no public PoC or in-the-wild exploitation reported.
  • Security press (Cyber Security News, Cyberpress) report on the advisory, emphasizing sandbox-escape and remote-code-execution potential and urging immediate updates.

Sources cited for Multiple Vulnerabilities in Firefox 152 Enable Remote Code

Detection coverage for TL-2026-0855

As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0855 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats