Executive brief
Mozilla Firefox and Thunderbird are widely used web browsing and email applications. Multiple memory safety vulnerabilities were identified that could allow an attacker to potentially take control of a user's computer or execute unauthorized commands. These issues are typically triggered when the application processes specially crafted web content or malicious scripts.
Technical details
This advisory covers a collection of memory safety bugs (CWE-787) identified in Firefox and Thunderbird. The root cause involves various memory corruption issues that, while not individually detailed in the high-level advisory, collectively present a risk of arbitrary code execution. The attack vector is remote via the network, typically requiring a user to visit a malicious website or interact with malicious content that triggers the memory corruption. In Thunderbird, the risk is mitigated during standard email reading as scripting is disabled, but remains a threat in browser-like contexts. The vulnerabilities are resolved in Firefox 148 and Thunderbird 148.
Affected products
- Mozilla Firefox < 148
- Mozilla Thunderbird < 148
Timeline
- 2026-02-24: advisory: Mozilla Foundation Security Advisory published
- 2026-02-24: patched: Fixed in Firefox 148 and Thunderbird 148
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1756056%2C1999402%2C2004872%2C2006037%2C2012855
- https://www.mozilla.org/security/advisories/mfsa2026-13/
- https://www.mozilla.org/security/advisories/mfsa2026-16/
- https://access.redhat.com/security/cve/CVE-2026-2807
- https://bugzilla.redhat.com/show_bug.cgi?id=2442296
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2807.json