Junglewise Threat Intelligence

CVE-2026-2799: Mozilla Firefox and Thunderbird use-after-free in DOM Core & HTML

CVE-2026-2799 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are affected by a critical security vulnerability in their core web page processing engine. An attacker could exploit this flaw to potentially execute unauthorized code or crash the application when a user visits a malicious website or views certain content. This could lead to a full system compromise or the theft of sensitive personal data.

Technical details

A use-after-free (UAF) vulnerability was identified in the DOM: Core & HTML component of Mozilla's rendering engine. The flaw occurs when the application continues to use a memory pointer after it has been freed, which can be triggered by specially crafted web content. An unauthenticated remote attacker can exploit this to achieve arbitrary code execution or cause a denial-of-service (browser crash). While Thunderbird is also affected, the risk is mitigated in email contexts where scripting is disabled, though it remains vulnerable in browser-like contexts. The issue is resolved in Firefox 148 and Thunderbird 148.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Thunderbird < 148

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: patched
  • 2026-02-24: advisory

References

Related threats