Mozilla releases Firefox 152 and ESR updates to fix 40 vulnerabilities, including high-severity bugs that could allow code execution

Mozilla released Firefox 152, Firefox ESR, Thunderbird, and Firefox for iOS updates to fix 40 security vulnerabilities affecting users across desktop and mobile products. The fixes include 13 high-severity issues such as use-after-free memory bugs, privilege-escalation flaws, sandbox escapes, incorrect boundary conditions, and JIT miscompilation problems; Mozilla said some memory-safety flaws could potentially allow arbitrary code execution.
Why it matters: People and organizations using Firefox or Thunderbird should update promptly because some of the patched bugs could let a malicious website or content run code or break browser protections. This affects both everyday users and enterprises that rely on Firefox ESR for managed deployments.

Sources

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
Ionut Arghire 2026.07.15 84% relevant
This source updates the Firefox 152 patch story with specific follow-on release details for Firefox 152.0.6, naming critical flaws CVE-2026-15718 and CVE-2026-15719 and noting public exploit code exists but no active exploitation has been observed.
Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities
Ionut Arghire 2026.06.17 100% relevant
The article establishes a distinct patch story for Mozilla products separate from the already tracked Chrome 149 update, with its own affected products, versions, and vulnerability count.
← Back to all stories