Executive brief
A critical security vulnerability has been identified in Mozilla Firefox and Thunderbird that could allow an attacker to bypass the software's security sandbox. This sandbox is a primary defense mechanism designed to prevent malicious websites or emails from accessing the rest of your computer. If exploited, an attacker could gain unauthorized access to your system, potentially leading to data theft or the installation of malware.
Technical details
A use-after-free vulnerability exists within the Disability Access APIs component of Mozilla browsers and mail clients. The flaw occurs when the application continues to use a pointer after the memory it references has been deallocated, leading to memory corruption. An attacker can leverage this to achieve a sandbox escape, moving from the restricted content process to the more privileged parent process or the host operating system. The vulnerability is reachable via network-delivered content and does not require user interaction according to the NVD CVSS 3.1 assessment. Patches are available in Firefox 149, Firefox ESR 140.9, and corresponding Thunderbird releases.
Affected products
- Mozilla Firefox < 149
- Mozilla Firefox ESR < 140.9
- Mozilla Thunderbird < 149
- Mozilla Thunderbird ESR < 140.9
Timeline
- 2026-03-24: disclosed
- 2026-03-24: advisory
- 2026-03-24: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2016373
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930
- https://access.redhat.com/errata/RHSA-2026:5931