Junglewise Threat Intelligence

CVE-2026-4686: Mozilla Firefox and Thunderbird out-of-bounds write in Canvas2D

CVE-2026-4686 · Severity: high · CVSS 7.5 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the Canvas2D graphics component of Mozilla Firefox and Thunderbird. This component is responsible for rendering 2D shapes and images within the browser. An exploit could allow an attacker to cause the application to crash, potentially leading to a denial-of-service or further system instability.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the Graphics: Canvas2D component of Mozilla Firefox and Thunderbird. The flaw is caused by incorrect boundary conditions when processing graphics data. A remote attacker could exploit this vulnerability without authentication or user interaction to cause a memory corruption, typically resulting in a denial-of-service (application crash). Red Hat's assessment also identifies this as an out-of-bounds write, which in some contexts can lead to arbitrary code execution, though the primary reported impact in the CVSS vector is on availability. The issue is resolved in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and Thunderbird 149/140.9.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 115.34, < 140.9
  • Mozilla Thunderbird < 149, < 140.9

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: patched
  • 2026-03-24: advisory

References

Related threats