Executive brief
Mozilla Firefox and Thunderbird are popular open-source web browsers and email clients. A critical vulnerability in the component responsible for processing audio and video content could allow an attacker to compromise the application. If exploited, this could lead to unauthorized access to user data, system instability, or the execution of malicious code on the user's device.
Technical details
An integer overflow vulnerability exists within the Audio/Video component of Mozilla Firefox and Thunderbird. The flaw is triggered when processing specially crafted media content, leading to memory corruption. While the specific root cause is restricted in Bugzilla, the CVSS 3.1 score of 9.8 suggests a network-based attack vector with no authentication or user interaction required, potentially allowing for remote code execution. The vulnerability was addressed by improving integer handling and boundary checks in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 115.33, < 140.8
- Mozilla Thunderbird < 148, < 140.8
Timeline
- 2026-02-24: disclosed
- 2026-02-24: patched
- 2026-02-24: advisory
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2014883
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338