Junglewise Threat Intelligence

CVE-2026-10701: Mozilla Firefox incorrect boundary conditions in Graphics Text component

CVE-2026-10701 · Severity: info · CVSS 7.5 · Published 2026-06-02

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox, a widely used web browser, contained a security flaw in how it handles text rendering. An attacker could potentially exploit this by tricking a user into visiting a malicious website, leading to a browser crash or the execution of unauthorized code. This could result in the theft of sensitive information or a compromise of the user's computer.

Technical details

A vulnerability exists in the Mozilla Firefox 'Graphics: Text' component due to incorrect boundary conditions (likely a buffer overflow or out-of-bounds access). The flaw is triggered when the browser processes specifically crafted text content, which can be delivered via a malicious website. An attacker who successfully exploits this could achieve remote code execution (RCE) within the context of the browser process or cause the application to crash (DoS). The issue is fixed in Firefox version 151.0.3.

Affected products

  • Mozilla Firefox < 151.0.3

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: patched
  • 2026-06-02: advisory

References

Related threats