CVE-2026-14241
published 2026-06-30CVE-2026-14241: Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.23%
14.0th percentile
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 152.0.4 | Firefox 152.0.4 |
| mozilla | firefox | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Mozilla
Mozilla Foundation Security Advisory 2026-62: CVE-2026-14241
vendor_mozilla
CVE-2026-14241 Mozilla Foundation Security Advisory 2026-62: CVE-2026-14241
Mozilla Foundation Security Advisory 2026-62
CVE: CVE-2026-14241
Product: Firefox
Impact: high
Fixed in: Firefox 152.0.4
GHSA
Memory safety bugs present in Firefox 152.0.3.
ghsa_unreviewed·2026-06-30
CVE-2026-14241 [CRITICAL] CWE-787 Memory safety bugs present in Firefox 152.0.3.
Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4.
VulDB
Mozilla Firefox up to 152.0.3 memory corruption (EUVD-2026-40321)
vuldb·2026-06-30
CVE-2026-14241 [CRITICAL] Mozilla Firefox up to 152.0.3 memory corruption (EUVD-2026-40321)
A vulnerability was found in Mozilla Firefox up to 152.0.3. It has been rated as critical. The impacted element is an unknown function. The manipulation leads to memory corruption.
This vulnerability is listed as CVE-2026-14241. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-30
Published