Junglewise Threat Intelligence

CVE-2026-2763: Mozilla Firefox and Thunderbird use-after-free in JavaScript Engine

CVE-2026-2763 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular web browsing and email applications. A critical vulnerability in their JavaScript engine could allow an attacker to execute malicious code on a user's system if they visit a specially crafted website or view a malicious email. This could lead to a total compromise of the user's data, unauthorized access to sensitive information, or the installation of malware.

Technical details

A use-after-free vulnerability exists in the JavaScript Engine component of Mozilla Firefox, Firefox ESR, and Thunderbird. The flaw is triggered during the processing of JavaScript content, where the engine attempts to access memory that has already been deallocated. An attacker can exploit this by enticing a user to visit a malicious webpage or open a malicious email, leading to memory corruption. This can be leveraged to achieve remote code execution (RCE) within the context of the application. The vulnerability is fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, and Thunderbird 148/140.8.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Firefox ESR < 115.33, < 140.8
  • Mozilla Thunderbird < 148, < 140.8

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: patched

References

Related threats