CVE-2024-7526: Mozilla Firefox
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Affected products
- Mozilla Firefox: before 129.0 (fixed in 129.0)
- Mozilla Firefox ESR: before 115.14.0 (fixed in 115.14.0); version 128.0 only
- Mozilla Thunderbird: before 115.14.0 (fixed in 115.14.0); version 128.0.1 only
Published 2024-08-06. Last modified 2026-06-17.