CVE-2020-12387: Mozilla Firefox

High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.

A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

Affected products

  • Mozilla Firefox: before 76.0 (fixed in 76.0)
  • Mozilla Firefox ESR: before 68.8.0 (fixed in 68.8.0)
  • Mozilla Thunderbird: before 68.8.0 (fixed in 68.8.0)

Published 2020-05-26. Last modified 2026-06-17.