Executive brief
Mozilla Firefox and Thunderbird are affected by a critical security vulnerability in their core web page processing engine. An attacker could exploit this flaw to potentially execute unauthorized code or crash the application when a user visits a malicious website or views certain content. This could lead to a full system compromise or the theft of sensitive personal data.
Technical details
A use-after-free (UAF) vulnerability was identified in the DOM: Core & HTML component of Mozilla's rendering engine. The flaw occurs when the application continues to use a memory pointer after it has been freed, which can be triggered by specially crafted web content. An unauthenticated remote attacker can exploit this to achieve arbitrary code execution or cause a denial-of-service (browser crash). While Thunderbird is also affected, the risk is mitigated in email contexts where scripting is disabled, though it remains vulnerable in browser-like contexts. The issue is resolved in Firefox 148 and Thunderbird 148.
Affected products
- Mozilla Firefox < 148
- Mozilla Thunderbird < 148
Timeline
- 2026-02-24: disclosed
- 2026-02-24: patched
- 2026-02-24: advisory
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2014551
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://access.redhat.com/security/cve/CVE-2026-2799
- https://bugzilla.redhat.com/show_bug.cgi?id=2442303
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2799.json