惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
雷峰网
雷峰网
S
SegmentFault 最新的问题
博客园 - 【当耐特】
博客园_首页
量子位
爱范儿
爱范儿
博客园 - 叶小钗
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
V
V2EX
美团技术团队
V
Visual Studio Blog
博客园 - 三生石上(FineUI控件)
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
博客园 - 聂微东
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Cloudflare Blog
宝玉的分享
宝玉的分享
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Multiple Vulnerabilities in Firefox 152 Enables Remote Co...
Abinaya · 2026-06-18 · via Cyber Security News

Mozilla has released Firefox 152 to address multiple high-severity vulnerabilities that could allow remote code execution (RCE) and sandbox escape attacks.

The security advisory, published on June 16, 2026, highlights a wide range of flaws affecting core browser components and emphasizes the urgency for users to update immediately.

Several of the patched vulnerabilities are classified as high impact, primarily involving memory safety issues, use-after-free bugs, and privilege escalation flaws.

These vulnerabilities can be exploited by attackers through specially crafted web content, potentially allowing arbitrary code execution on affected systems.

Multiple Vulnerabilities in Firefox 152

Notable high-risk vulnerabilities include:

CVE-2026-12289: A privilege escalation flaw in the WebRender component that could allow attackers to gain elevated access.

CVE-2026-12291: A use-after-free vulnerability in the HTTP networking component, leading to memory corruption.

CVE-2026-12293: A use-after-free issue in the WebGPU component that could be leveraged for code execution.

CVE-2026-12294 to CVE-2026-12297: Multiple sandbox escape vulnerabilities impacting DOM Workers, Navigation, and process sandboxing mechanisms.

CVE-2026-12299: A JIT miscompilation bug in DOM and HTML components that could result in unpredictable execution behavior.

Additionally, Mozilla reported several memory safety bugs (e.g., CVE-2026-12290, CVE-2026-12298, CVE-2026-12326, CVE-2026-12328) that demonstrated memory corruption.

Such flaws are particularly dangerous because attackers can exploit them to execute arbitrary code remotely. The presence of multiple sandbox escape vulnerabilities significantly increases the attack surface.

In a typical exploit chain, an attacker may first exploit a memory corruption flaw to gain code execution within the browser, then use a sandbox escape vulnerability to break out of the browser’s security boundaries and compromise the underlying system.

For example, combining CVE-2026-12291 (use-after-free) with CVE-2026-12294 (sandbox escape in DOM Workers) could enable a full browser-to-system compromise.

In addition to high-risk flaws, Mozilla addressed several moderate- and low-severity vulnerabilities, including a same-origin policy bypass (CVE-2026-12304) affecting cookie handling.

Information disclosure issues in WebGPU and Password Manager components multiple mitigation bypass vulnerabilities in DOM security mechanisms.

Denial-of-service (DoS) issues in media playback and graphics components. Numerous memory safety bugs across various modules.

While these issues are less severe individually, they can still be chained with other vulnerabilities to enhance attack effectiveness.

According to advisory MFSA 2026-57, Mozilla has patched these vulnerabilities in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 152, while older versions remain vulnerable.

Users and organizations should update Firefox to version 152 or later, apply the latest ESR updates, enable automatic updates, and monitor systems for signs of suspicious browser activity or exploitation attempts.

The Firefox 152 update addresses a critical set of vulnerabilities, many of which could be chained to achieve remote code execution and full system compromise.

Given the presence of active exploit primitives such as memory corruption and sandbox escapes, timely patching is essential to maintaining browser security.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.