Junglewise Threat Intelligence

CVE-2026-2797: Mozilla Firefox and Thunderbird use-after-free in JavaScript GC

CVE-2026-2797 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are affected by a critical security flaw in their JavaScript engine. This vulnerability could allow an attacker to execute malicious code or crash the application when a user visits a specially crafted website or interacts with browser-like content. Users should update to version 148 or later to protect their data and systems from potential compromise.

Technical details

A use-after-free (UAF) vulnerability was identified in the JavaScript: GC (Garbage Collection) component of Mozilla Firefox and Thunderbird. The flaw occurs when the engine attempts to access memory that has already been freed during garbage collection cycles. An attacker can exploit this by delivering malicious JavaScript via a website or browser-like context, potentially achieving remote code execution (RCE) or a denial-of-service (DoS) condition. The vulnerability is reachable over the network without prior authentication. It has been addressed in Firefox 148 and Thunderbird 148.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Thunderbird < 148

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: advisory
  • 2026-02-24: patched

References

Related threats