Executive brief
Mozilla Firefox and Thunderbird are affected by a critical security flaw in their JavaScript engine. This vulnerability could allow an attacker to execute malicious code or crash the application when a user visits a specially crafted website or interacts with browser-like content. Users should update to version 148 or later to protect their data and systems from potential compromise.
Technical details
A use-after-free (UAF) vulnerability was identified in the JavaScript: GC (Garbage Collection) component of Mozilla Firefox and Thunderbird. The flaw occurs when the engine attempts to access memory that has already been freed during garbage collection cycles. An attacker can exploit this by delivering malicious JavaScript via a website or browser-like context, potentially achieving remote code execution (RCE) or a denial-of-service (DoS) condition. The vulnerability is reachable over the network without prior authentication. It has been addressed in Firefox 148 and Thunderbird 148.
Affected products
- Mozilla Firefox < 148
- Mozilla Thunderbird < 148
Timeline
- 2026-02-24: disclosed
- 2026-02-24: advisory
- 2026-02-24: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2013561
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://access.redhat.com/security/cve/CVE-2026-2797
- https://bugzilla.redhat.com/show_bug.cgi?id=2442330
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2797.json