Executive brief
Mozilla Firefox and Thunderbird are popular open-source web browsers and email clients. A critical vulnerability in the Web Audio component could allow an attacker to compromise the application by processing malicious audio content. This could lead to unauthorized access to user data, service instability, or the execution of malicious code on the user's system.
Technical details
The vulnerability is classified as an 'Incorrect Boundary Condition' (CWE-119) within the Web Audio component of Mozilla browsers and email clients. It is triggered when the application processes specially crafted audio content that violates expected memory boundaries. An attacker can exploit this remotely without authentication, potentially leading to a heap buffer overflow or similar memory corruption. Successful exploitation could allow for arbitrary code execution within the context of the application. The issue has been addressed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 115.33, < 140.8
- Mozilla Thunderbird < 148, < 140.8
- Red Hat Enterprise Linux Server (v. 7 ELS) 7
Timeline
- 2026-02-24: advisory: Mozilla published security advisories MFSA2026-13, MFSA2026-14, and MFSA2026-15.
- 2026-02-24: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2014832
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338