Executive brief
A security vulnerability has been identified in Mozilla Firefox and Thunderbird's internal communication system. This flaw could allow an attacker to execute malicious code or crash the application if a user visits a specially crafted website or opens a malicious file. This could lead to the theft of sensitive personal data or full control over the user's browser session.
Technical details
A use-after-free (UAF) vulnerability exists in the IPC component of Mozilla Gecko-based applications, specifically within the ChildProcessChannelListener::OnChannelReady function. The flaw is triggered during cross-process redirects when a callback is extracted from a tracking map and subsequently accessed after its underlying memory may have been freed. An attacker can exploit this by enticing a user to load a malicious HTML file (locally or via the web), potentially leading to arbitrary code execution within the context of the content process. The vulnerability has been addressed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, and corresponding Thunderbird releases.
Affected products
- Mozilla Firefox < 147
- Mozilla Firefox ESR < 115.32, < 140.7
- Mozilla Thunderbird < 147, < 140.7
- Red Hat Enterprise Linux 7, 10
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched
- 2026-01-13: advisory
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1924125
- https://www.mozilla.org/security/advisories/mfsa2026-01/
- https://www.mozilla.org/security/advisories/mfsa2026-02/
- https://www.mozilla.org/security/advisories/mfsa2026-03/
- https://www.mozilla.org/security/advisories/mfsa2026-04/
- https://www.mozilla.org/security/advisories/mfsa2026-05/
- https://access.redhat.com/errata/RHSA-2026:0667