Executive brief
A critical vulnerability has been identified in Mozilla Firefox and Thunderbird's WebAssembly component, which is used to run high-performance applications in the browser. An attacker could exploit this flaw to execute unauthorized code or gain control over the affected application. This could lead to the theft of sensitive user data or a complete compromise of the user's browsing session.
Technical details
The vulnerability is a JIT (Just-In-Time) miscompilation within the JavaScript: WebAssembly component of Mozilla browsers. It is classified as a type confusion vulnerability (CWE-843), where the engine accesses a resource using an incompatible type due to errors during the compilation of WebAssembly code. An attacker can exploit this by providing malicious WebAssembly content, potentially leading to arbitrary code execution within the context of the browser process. While Thunderbird is affected, the risk is lower in email contexts where scripting is disabled, but remains high in browser-like contexts. The issue was fixed in Firefox 148 and Thunderbird 148.
Affected products
- Mozilla Firefox < 148
- Mozilla Thunderbird < 148
Timeline
- 2026-02-24: disclosed
- 2026-02-24: advisory
- 2026-02-24: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2013165
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://access.redhat.com/security/cve/CVE-2026-2796
- https://bugzilla.redhat.com/show_bug.cgi?id=2442301
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2796.json