Executive brief
Mozilla Firefox and Thunderbird are popular web browsing and email applications. A critical vulnerability in their JavaScript engine could allow an attacker to execute malicious code on a user's system if they visit a specially crafted website or view a malicious email. This could lead to a total compromise of the user's data, unauthorized access to sensitive information, or the installation of malware.
Technical details
A use-after-free vulnerability exists in the JavaScript Engine component of Mozilla Firefox, Firefox ESR, and Thunderbird. The flaw is triggered during the processing of JavaScript content, where the engine attempts to access memory that has already been deallocated. An attacker can exploit this by enticing a user to visit a malicious webpage or open a malicious email, leading to memory corruption. This can be leveraged to achieve remote code execution (RCE) within the context of the application. The vulnerability is fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, and Thunderbird 148/140.8.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 115.33, < 140.8
- Mozilla Thunderbird < 148, < 140.8
Timeline
- 2026-02-24: disclosed
- 2026-02-24: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2012018
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338