Junglewise Threat Intelligence

CVE-2026-2765: Mozilla Firefox and Thunderbird use-after-free in JavaScript Engine

CVE-2026-2765 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Red Hat Enterprise Linux, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla, Red Hat.

Executive brief

A critical vulnerability exists in the JavaScript engine used by Mozilla Firefox and Thunderbird. This flaw could allow an attacker to execute malicious code or crash the application when a user visits a specially crafted website or opens a malicious email. Successful exploitation could lead to full system compromise or the theft of sensitive personal data.

Technical details

A use-after-free vulnerability was identified in the JavaScript Engine component of Mozilla browsers and mail clients. The flaw occurs when the engine attempts to access memory that has already been deallocated, typically during complex script execution. An attacker can exploit this by enticing a user to process malicious web content or emails, leading to arbitrary code execution or a denial-of-service (browser crash) within the context of the application. The vulnerability is addressed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. Red Hat has also issued advisories for affected Enterprise Linux versions.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Firefox ESR < 140.8
  • Mozilla Thunderbird < 148
  • Mozilla Thunderbird ESR < 140.8
  • Red Hat Enterprise Linux 7, 10.0

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: patched
  • 2026-02-24: advisory

References

Related threats