Junglewise Threat Intelligence

CVE-2026-4684: Mozilla Firefox and Thunderbird use-after-free in WebRender

CVE-2026-4684 · Severity: high · CVSS 7.5 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A race condition in the WebRender component of Mozilla Firefox and Thunderbird could allow for a use-after-free memory error. This component is responsible for rendering web content and graphics. If exploited, an attacker could potentially execute arbitrary code or cause the application to crash, though Thunderbird is generally less susceptible unless browser-like features are used.

Technical details

A race condition exists within the Graphics: WebRender component of Mozilla browsers and mail clients, leading to a use-after-free (UAF) vulnerability. The flaw is triggered during the processing of graphical content, where timing issues in memory management allow an attacker to reference memory after it has been freed. This can lead to memory corruption and potentially arbitrary code execution within the context of the application. The vulnerability is reachable via malicious web content; however, in Thunderbird, the risk is mitigated during standard email reading as scripting is disabled by default. Patches are available in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and Thunderbird 149/140.9.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 115.34, < 140.9
  • Mozilla Thunderbird < 149
  • Mozilla Thunderbird ESR < 140.9

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: patched
  • 2026-03-24: advisory

References

Related threats