Executive brief
A security vulnerability has been identified in the HTML processing component of Mozilla Firefox and Thunderbird. This flaw could allow an attacker to bypass built-in security protections designed to prevent unauthorized actions or data access. If exploited, it could lead to a compromise of the user's browser or email client, potentially exposing sensitive information or allowing for further malicious activity.
Technical details
A mitigation bypass vulnerability exists in the DOM: HTML Parser component of Mozilla browsers and mail clients. The flaw allows for the circumvention of security mitigations, which, according to CVSS metrics, can be exploited over the network without user interaction or special privileges. While specific root cause details are restricted in the associated Bugzilla report, the vulnerability is classified as an authentication or mitigation bypass (CWE-288) that can lead to high impacts on confidentiality, integrity, and availability. The issue is resolved in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, and Thunderbird versions 148 and 140.8.
Affected products
- Mozilla Firefox < 148
- Mozilla Firefox ESR < 115.33, < 140.8
- Mozilla Thunderbird < 148, < 140.8
Timeline
- 2026-02-24: disclosed
- 2026-02-24: patched
- 2026-02-24: advisory
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2015199
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-14/
- https://www.mozilla.org/security/advisories/mfsa2026-15/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://www.mozilla.org/security/advisories/mfsa2026-17/
- https://access.redhat.com/errata/RHSA-2026:3338