# Multiple Vulnerabilities in Firefox 152 Enable Remote Code Execution and Sandbox Escape (MFSA 2026-57)

> Mozilla's MFSA 2026-57 advisory fixes 39 vulnerabilities in Firefox 152, including use-after-free, memory-safety/corruption, JIT miscompilation, and four distinct sandbox-escape flaws that, chained, allow remote code execution when a victim loads specially crafted web content. Fixes are also shipped in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 152.

- **Published:** 2026-06-18T00:00:00Z
- **Last reviewed:** 2026-06-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0855
- **ID:** TL-2026-0855
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-12289, CVE-2026-12290, CVE-2026-12291, CVE-2026-12292, CVE-2026-12293, CVE-2026-12294, CVE-2026-12295, CVE-2026-12296, CVE-2026-12297, CVE-2026-12298, CVE-2026-12299, CVE-2026-12300, CVE-2026-12301, CVE-2026-12302, CVE-2026-12303, CVE-2026-12304, CVE-2026-12305, CVE-2026-12306, CVE-2026-12307, CVE-2026-12308, CVE-2026-12309, CVE-2026-12310, CVE-2026-12311, CVE-2026-12312, CVE-2026-12313, CVE-2026-12314, CVE-2026-12315, CVE-2026-12316, CVE-2026-12317, CVE-2026-12318, CVE-2026-12319, CVE-2026-12320, CVE-2026-12321, CVE-2026-12322, CVE-2026-12323, CVE-2026-12324, CVE-2026-12325, CVE-2026-12326, CVE-2026-12327, CVE-2026-12328

## Description

On June 16, 2026 Mozilla published Security Advisory MFSA 2026-57, addressing 39 vulnerabilities in Firefox 152 (with parallel fixes in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 152). The advisory is dominated by classic browser memory-safety issues reachable from untrusted web content over the network attack vector, requiring only that a user visit or render a malicious page (drive-by / client-side execution).

The highest-impact issues are a use-after-free in the HTTP networking stack (CVE-2026-12291) and a use-after-free in the WebGPU graphics subsystem (CVE-2026-12293), both leading to memory corruption that can be leveraged for arbitrary code execution inside the content process. A JIT miscompilation in DOM: Core & HTML (CVE-2026-12299) produces unpredictable execution behavior that can bypass memory protections, and a WebAssembly JIT miscompilation (CVE-2026-12321) is also fixed. Multiple aggregate memory-safety roll-up bugs (CVE-2026-12290, 12298, 12326, 12328) carry High impact and are described by Mozilla as showing evidence of memory corruption that, with sufficient effort, could be exploited to run arbitrary code.

Four High-severity sandbox-escape vulnerabilities are the most strategically significant: CVE-2026-12294 (DOM: Workers), CVE-2026-12295 (DOM: Navigation), CVE-2026-12296 (Security: Process Sandboxing), and CVE-2026-12297 (incorrect boundary conditions in Networking). A real-world exploit chain pairs one of the content-process memory-corruption primitives (e.g., the HTTP or WebGPU UAF) with a sandbox escape to break out of the renderer/content sandbox and interact with the underlying operating system, and optionally CVE-2026-12289 (privilege escalation in Graphics: WebRender) to elevate privileges on the host. Additional issues include same-origin-policy bypass via cookie handling (CVE-2026-12304), DOM security mitigation bypasses (CVE-2026-12302, 12315, 12316), information disclosure paired with sandbox escape (CVE-2026-12311, 12313), WebGPU information disclosure (CVE-2026-12303), Password Manager information disclosure (CVE-2026-12320), GTK widget clickjacking (CVE-2026-12322), DOM spoofing (CVE-2026-12323), and several denial-of-service flaws in media playback (CVE-2026-12319) and graphics/ImageLib (CVE-2026-12325).

Mozilla provided no CVSS base scores in the advisory and there is no public proof-of-concept or confirmed in-the-wild exploitation reported in the source material; severity is therefore tracked using Mozilla's own High/Moderate/Low impact ratings. Given the demonstrated RCE-plus-sandbox-escape potential against one of the most widely deployed browsers, organizations should treat patch rollout to Firefox 152 / ESR 140.12 / ESR 115.37 / Thunderbird 152 as a priority.

## MITRE ATT&CK

- T1592.002 Software
- T1189 Drive-by Compromise
- T1566.002 Spearphishing Link
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1059.007 JavaScript
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1555.003 Credentials from Web Browsers
- T1212 Exploitation for Credential Access
- T1539 Steal Web Session Cookie
- T1518 Software Discovery
- T1185 Browser Session Hijacking
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1499 Endpoint Denial of Service
- T1499.004 Application or System Exploitation

## Sources

- [Mozilla Foundation Security Advisory MFSA 2026-57 — Security Vulnerabilities fixed in Firefox 152](https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/)
- [Multiple Vulnerabilities in Firefox 152 Enables Remote Code Execution Attacks](https://cybersecuritynews.com/firefox-152-vulnerabilities/)
- [Critical Firefox 152 Vulnerabilities Enable Remote Code Execution](https://cyberpress.org/critical-firefox-152-vulnerabilities/)
- [Mozilla Foundation Security Advisories index](https://www.mozilla.org/en-US/security/advisories/)
- [Security Advisories for Firefox — Known Vulnerabilities](https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/)
- [CVE-2026-12302: Vulnerability in Mozilla Firefox — OffSeq Threat Radar](https://radar.offseq.com/threat/cve-2026-12302-vulnerability-in-mozilla-firefox-5ef54665)
- [Mozilla Firefox Security Vulnerabilities in 2026 — stack.watch](https://stack.watch/product/mozilla/firefox/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0855
