Executive brief
Mozilla Firefox and Thunderbird are affected by a critical security flaw in their JavaScript engine, which is responsible for running interactive content on websites and in emails. An attacker could exploit this vulnerability to execute unauthorized code or crash the application by tricking the software into using memory that has already been released. This could lead to a full system compromise or the theft of sensitive user data. Users should update to the latest versions of Firefox and Thunderbird immediately to protect their systems.
Technical details
A use-after-free (UAF) vulnerability was identified in the Just-In-Time (JIT) compiler component of the Mozilla JavaScript Engine (SpiderMonkey). The flaw occurs when the engine attempts to access memory that has been previously deallocated, typically during complex script execution or optimization phases. An unauthenticated remote attacker can exploit this by providing specially crafted JavaScript content via a webpage or email. Successful exploitation can lead to arbitrary code execution within the context of the application or a process crash. The vulnerability is addressed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 140.8
- Mozilla Thunderbird < 148
- Mozilla Thunderbird < 140.8
- Red Hat Enterprise Linux Server (v. 7 ELS) affected
- Red Hat Enterprise Linux AppStream EUS (v. 10.0) affected
Timeline
- 2026-02-24: advisory: Mozilla published security advisories MFSA2026-13 and MFSA2026-15.
- 2026-02-24: patched: Fixed versions released for Firefox and Thunderbird.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2013583
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338
- https://access.redhat.com/errata/RHSA-2026:3339