These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A same-origin policy bypass vulnerability was discovered in the Networking: Cookies component of Firefox. This vulnerability, tracked as CVE-2026-12304, was fixed in Firefox 152 and Firefox ESR 140.12. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-12304) and last modified on [cveModifiedAt](https://www.cve.org/CVERecord?id=CVE-2026-12304).
CVE-2026-12303 is an information disclosure vulnerability due to incorrect boundary conditions in the Graphics: WebGPU component. The issue was fixed in Firefox 152. According to [nvd](https://nvd.nist.gov/vuln/detail/CVE-2026-12303), this CVE was published and modified on 2026-06-16T13:16:30.557Z. For more information, refer to the [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-12303) and [Mozill [truncated]
A mitigation bypass vulnerability was discovered in the DOM: Security component. This issue was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. The vulnerability was publicly disclosed on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-12302).
A memory safety bug was fixed in Firefox 152. This vulnerability was fixed in Firefox 152. The bug was reported to Mozilla via Bugzilla and addressed in the Mozilla Security Advisories.
A memory safety bug was fixed in Firefox 152. This vulnerability was fixed in Firefox 152. The bug was reported to Mozilla via Bugzilla [ref-4]. For more information, refer to Mozilla's security advisory [ref-5].
CVE-2026-12299 is a vulnerability in the Firefox browser, specifically affecting the JIT (Just-In-Time) compilation process in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
CVE-2026-12298 is a memory safety bug that was fixed in Firefox 152 and Firefox ESR 140.12. The bug was reported and fixed, with no evidence of public exploits or additional details available.
A sandbox escape vulnerability was discovered in the Networking component of Firefox, caused by incorrect boundary conditions. This issue was addressed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
CVE-2026-12296 is a sandbox escape vulnerability in the Security: Process Sandboxing component. The vulnerability was fixed in Firefox 152 and Firefox ESR 140.12. The CVE was published and modified on June 16, 2026.
CVE-2026-12295 is a vulnerability in the DOM: Navigation component that allows for sandbox escape. This issue was addressed by Mozilla in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
CVE-2026-12294 is a vulnerability in the DOM: Workers component that allows for sandbox escape. The vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. The CVE was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-12294) and last modified on [cveModifiedAt](https://www.cve.org/CVERecord?id=CVE-2026-12294).
CVE-2026-12293 is a use-after-free vulnerability in the Graphics: WebGPU component of Firefox. This issue was fixed in Firefox 152. The vulnerability was published on [cvePublishedAt] and has not been associated with a CVSS score or severity level.
CVE-2026-12292 is a vulnerability caused by incorrect boundary conditions in the Web Audio component. It was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-12292) and modified on [cveModifiedAt]. The vulnerability was fixed in Firefox 152 and Firefox ESR 140.12. For more information, refer to [ref-5](https://www.mozilla.org/security/advisories/mfsa2026-57/) and [ref-6](https://www [truncated]
A memory safety bug was fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37. The bug was reported to Mozilla via Bugzilla [ref-4]. Mozilla has released advisories for this vulnerability: [ref-5], [ref-6], and [ref-7].
CVE-2026-12289 is a privilege escalation vulnerability in the Graphics: WebRender component of Firefox. This issue was addressed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.
CVE-2026-11799 is a UXSS (User Experience Security issue, potentially leading to Spoofing) vulnerability affecting Focus for iOS and Klar for iOS. The issue is related to Webkit navigation. The vulnerability was fixed in Focus for iOS 151.3.1 and Klar for iOS 151.3.1. The CVSS score for this vulnerability is 7.5, indicating a HIGH severity level. The vulnerability was published on [cve-org](https://www.cv [truncated]
A medium-severity cross-site scripting vulnerability in Firefox for iOS Reader View allowed malicious pages to inject unescaped HTML via JSON-LD metadata. The injected markup could alter Reader View behavior and exfiltrate sensitive URL parameters, which could then be leveraged to access internal pages and achieve arbitrary JavaScript execution in an internal origin. Mozilla fixed this issue in Firefox for iOS 151.2.
A cross-site scripting (XSS) vulnerability in Firefox for iOS Reader View allowed malicious pages to inject arbitrary JavaScript through template placeholder substitution. The root cause was an ordering issue in the Reader View HTML template processing: page content was substituted before internal placeholders were replaced, enabling attacker-controlled placeholder strings to be later populated with JSON- [truncated]
CVE-2026-9078 is a visual spoofing vulnerability in Firefox for iOS affecting link preview UI surfaces. The issue involves incorrect display of specially crafted right-to-left (RTL) and internationalized domain names (IDNs), where a malicious RTL hostname could visually reorder portions of the displayed domain to make attacker-controlled sites appear as trusted origins. This represents a user interface de [truncated]
CVE-2026-8974 is a high-severity Mozilla memory safety issue tied to Firefox and Thunderbird. The vendor and NVD describe evidence of memory corruption, with the possibility that exploitation could have led to arbitrary code execution. Mozilla released fixes in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. Because the CVSS vector includes user interaction, the main risk is on s [truncated]
CVE-2026-8973 is a high-severity Mozilla memory safety issue affecting Thunderbird and Firefox releases before 151. NVD says the bug class involved memory corruption and maps it to CWE-119. Because the issue is network-reachable and requires user interaction, it is a meaningful exposure for environments running affected Mozilla clients until they are updated to 151 or later.
CVE-2026-8972 is a Mozilla privilege-escalation vulnerability in the WebRTC: Audio/Video component. NVD rates it 8.8 High with a network attack vector, low attack complexity, no attacker privileges, and user interaction required. Mozilla’s advisory references indicate the issue was fixed in Firefox 151 and Thunderbird 151, and NVD lists affected versions as those before 151.0.0.
CVE-2026-8971 is a Mozilla same-origin policy bypass affecting the Networking: JAR component. According to the official NVD record, the issue was fixed in Firefox 151 and Thunderbird 151, and affected versions are those before 151.0.0. The vulnerability is network-exploitable, requires no privileges or user interaction, and carries limited confidentiality and integrity impact.
CVE-2026-8970 is a high-severity privilege escalation issue in Mozilla’s Security component. Mozilla states it was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. The NVD entry rates the issue 8.8 High and describes a network-reachable attack that requires user interaction, with potential high impact to confidentiality, integrity, and availability.
CVE-2026-8969 is a high-severity Mozilla vulnerability described as a mitigation bypass in the DOM: Security component. According to the official NVD record, it affects Firefox and Thunderbird versions before 151.0.0 and was fixed in Firefox 151 and Thunderbird 151. The supplied record indicates network reachability and required user interaction, with confidentiality and integrity impact rated high and av [truncated]
CVE-2026-8968 is a Mozilla vulnerability in the Audio/Video: Web Codecs component that can cause a denial of service through an invalid pointer condition. Mozilla states the issue was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
CVE-2026-8967 is a Mozilla information disclosure vulnerability in the Graphics: WebGPU component. NVD rates it HIGH severity with a CVSS 3.1 score of 7.5, and the published vector indicates network reachability, low attack complexity, no privileges required, no user interaction, and confidentiality impact only. Mozilla states the issue was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-8966 is a Mozilla information disclosure vulnerability in the IP Protection component. According to NVD and Mozilla’s advisories, it affects Firefox and Thunderbird versions before 151.0.0 and was fixed in Firefox 151 and Thunderbird 151. The CVSS 3.1 score is 7.5 (HIGH), reflecting network exposure, no user interaction, and high confidentiality impact.
CVE-2026-8965 is a high-severity information disclosure vulnerability in Mozilla’s DOM security component. NVD classifies it as CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), indicating a remotely reachable confidentiality-impact issue with no privileges or user interaction required. Mozilla fixed the issue in Firefox 151 and Thunderbird 151, and NVD lists affected Firefox and Thunderbird versions be [truncated]
CVE-2026-8964 is a Mozilla spoofing issue in the Popup Blocker component. Mozilla states the issue was fixed in Firefox 151 and Thunderbird 151. NVD rates it HIGH with network attack vector and no privileges required, but the available impact is limited to integrity.