Mozilla released Firefox 152 for desktop and web platforms alongside Firefox ESR 140.12.0 and 115.37.0, delivering browser, developer, and mobile updates that include experimental JPEG XL support in Firefox Labs, changes to the Notifications and Pointer Lock APIs, CSS field-sizing, PDF handling improvements, and new Android features such as AI-assisted tab grouping and enhanced link-sharing options.
The release also fixes 77 security vulnerabilities, with Mozilla stating that 60 were memory-safety bugs and that some could potentially be exploited for arbitrary code execution when processing specially crafted content. The patched issues include groups tracked as CVE-2026-12328, CVE-2026-12327, and CVE-2026-12326, making the update a significant security release for both standard and ESR Firefox users.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
As part of the Firefox 152 release, Mozilla fixed 77 security vulnerabilities, including issues tracked as CVE-2026-12328, CVE-2026-12327, and CVE-2026-12326. Mozilla said 60 of the fixed flaws were memory-safety bugs, some potentially exploitable for arbitrary code execution via specially crafted content.
Mozilla released Firefox 152 along with Firefox ESR 140.12.0 and 115.37.0 for desktop and web platforms. The release introduced multiple browser and developer-facing changes, including experimental JPEG XL support and API, CSS, PDF, and Android updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcemozilla.org
Open sourcebugzilla.mozilla.org
Open sourcedeveloper.mozilla.org
Open sourcedeveloper.mozilla.org
Open sourceopennet.ru
Open sourceopennet.me
Open sourcedeveloper.mozilla.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.