Executive brief
A critical vulnerability has been identified in the core web-page processing engine of Firefox and Thunderbird. This flaw could allow an attacker to potentially execute unauthorized code or crash the application when a user visits a malicious website or opens a specially crafted email. Organizations should update their web browsers and email clients to the latest versions to protect against potential data theft or system compromise.
Technical details
A vulnerability classified as 'undefined behavior' exists within the DOM: Core & HTML component of Mozilla-based products. While the specific root cause is described generally as undefined behavior, CISA-ADP has associated it with an out-of-bounds read (CWE-125), and Red Hat indicates it may involve memory corruption. The attack vector is network-based and requires no special privileges, potentially allowing for remote code execution or a complete denial of service. The issue was discovered by a research team using AI-assisted fuzzing (Claude from Anthropic) and has been patched in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, and corresponding Thunderbird releases.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 115.33, < 140.8
- Mozilla Thunderbird < 148, < 140.8
- Red Hat Enterprise Linux Server (v. 7 ELS) 7
Timeline
- 2026-02-24: advisory: Mozilla Foundation Security Advisory published
- 2026-02-24: patched: Fixed in Firefox 148 and ESR versions
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2014593
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338