Executive brief
Mozilla has released security updates to address multiple memory safety vulnerabilities in the Firefox web browser and Thunderbird email client. These flaws could potentially allow an attacker to corrupt the application's memory, leading to a complete system compromise or the ability to run unauthorized code. While Thunderbird is less susceptible during normal email reading because scripting is disabled, users of both applications should update immediately to protect their data and systems.
Technical details
This advisory covers a collection of memory safety bugs (CWE-119) identified by Mozilla developers and fuzzing teams. The vulnerabilities involve improper restriction of operations within the bounds of a memory buffer, which can result in memory corruption. An attacker could potentially exploit these flaws to achieve arbitrary code execution. The attack vector is typically remote via the network, though it may require high complexity or specific user interaction (such as visiting a malicious website or viewing malicious content in a browser-like context). The issues are resolved in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
Affected products
- Mozilla Firefox < 147
- Mozilla Firefox ESR < 140.7
- Mozilla Thunderbird < 147
- Mozilla Thunderbird ESR < 140.7
Timeline
- 2026-01-13: advisory: Initial Mozilla Foundation Security Advisory released.
- 2026-01-13: patched: Fixed versions released by Mozilla.
- 2026-01-15: advisory: Red Hat published related security errata.
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1964722%2C2000981%2C2003100%2C2003278
- https://www.mozilla.org/security/advisories/mfsa2026-01/
- https://www.mozilla.org/security/advisories/mfsa2026-03/
- https://www.mozilla.org/security/advisories/mfsa2026-04/
- https://www.mozilla.org/security/advisories/mfsa2026-05/
- https://access.redhat.com/errata/RHSA-2026:0667
- https://access.redhat.com/errata/RHSA-2026:0694