CVE-2026-15719
Modified Modified - Updated After Analysis

Heap Buffer Overflow in Firefox

Vulnerability report for CVE-2026-15719, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Mozilla Corporation

Description

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mozilla firefox to 152.0.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-15719 is not explicitly described in the provided context. However, based on the available information, this vulnerability was fixed in Firefox 152.0.6. The CVSS v3.1 score of 5.4 indicates a medium-severity issue with low confidentiality and integrity impacts, requiring user interaction over a network.

The context mentions that exploit code for this vulnerability is public, but there are no known attacks in the wild abusing this flaw. The assigner is [email protected], and the vulnerability is associated with Mozilla Firefox.

Detection Guidance

The provided context does not specify detection methods or commands for identifying this vulnerability on a network or system. Detection typically involves checking the installed version of Firefox to determine if it is vulnerable.

  • Verify the Firefox version: Run 'firefox --version' or check the 'About Firefox' section in the browser's menu to confirm if the installed version is 152.0.6 or later. Versions prior to 152.0.6 are vulnerable.

Since the vulnerability involves the JavaScript: WebAssembly component, monitoring for unusual WebAssembly-related activity in browser logs or network traffic may help, but specific detection commands are not provided in the context.

Impact Analysis

If you are using an affected version of Mozilla Firefox (prior to 152.0.6), this vulnerability could impact you in the following ways:

  • An attacker could exploit this flaw by tricking you into visiting a malicious website or interacting with crafted content.
  • Successful exploitation may lead to limited data disclosure (confidentiality impact) or minor modifications to data (integrity impact).

Since exploit code is publicly available, the risk of exploitation is higher, though no active attacks have been reported.

Compliance Impact

The impact on compliance depends on the nature of the data handled by the affected system and the specific regulations applicable to your organization.

  • GDPR: If the vulnerability leads to unauthorized access or disclosure of personal data, it could result in a violation of GDPR's data protection requirements, potentially leading to fines or legal action.
  • HIPAA: If the vulnerability affects systems processing protected health information (PHI), it could lead to a breach of HIPAA's security rules, requiring notification and potential penalties.

Since the vulnerability has a low confidentiality and integrity impact, the risk to compliance may be limited, but organizations should still assess their exposure and apply the available patch to mitigate potential risks.

Mitigation Strategies

The vulnerability was fixed in Firefox 152.0.6. The immediate step to mitigate this issue is to ensure all systems are updated to this version or later.

  • Update Firefox to version 152.0.6 or newer. This can be done via the browser's built-in update mechanism or by downloading the latest version from Mozilla's official website.
  • If updating is not immediately possible, consider disabling WebAssembly in Firefox as a temporary workaround. This can be done by setting 'javascript.options.wasm' to 'false' in the browser's configuration (about:config).

Monitor Mozilla's security advisories for any additional guidance or patches related to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15719. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart