Executive brief
Mozilla Firefox and Thunderbird are popular web browsing and email applications used for accessing the internet and managing communications. A critical memory management flaw has been identified that could allow an attacker to potentially execute unauthorized code or crash the application. This occurs when the software incorrectly handles data in its internal web interface components, posing a risk to user data and system integrity if a user visits a malicious website or opens a specially crafted email.
Technical details
A use-after-free (UAF) vulnerability was identified in the DOM: Bindings (WebIDL) component of Mozilla browsers and mail clients. The flaw occurs due to improper memory management when handling WebIDL bindings, which are responsible for the interface between JavaScript and the C++ DOM implementation. An attacker can exploit this by enticing a user to visit a malicious webpage or view a crafted email, leading to memory corruption. This can result in a stable application crash or potentially arbitrary code execution within the context of the browser process. The vulnerability is addressed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, and corresponding Thunderbird versions.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 115.33, < 140.8
- Mozilla Thunderbird < 148, < 140.8
- Red Hat Red Hat Enterprise Linux Server (v. 7 ELS) affected
Timeline
- 2026-02-24: advisory: Mozilla Foundation Security Advisory published
- 2026-02-24: patched: Fixed in Firefox 148 and ESR versions
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2014585
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338