Junglewise Threat Intelligence

CVE-2026-4691: Mozilla Firefox and Thunderbird use-after-free in CSS Parsing and Computation

CVE-2026-4691 · Severity: critical · CVSS 9.8 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A critical vulnerability has been identified in Mozilla Firefox and Thunderbird's CSS engine, which handles how websites are styled and displayed. An attacker could exploit this flaw to potentially execute unauthorized code or crash the application by tricking the software into using memory that has already been released. This could lead to the theft of sensitive user data or a complete compromise of the user's workstation.

Technical details

A use-after-free vulnerability exists within the CSS Parsing and Computation component of Mozilla browsers and mail clients. The flaw is triggered during the processing of CSS content, where the application attempts to access memory that has been previously deallocated. An attacker can exploit this by providing specially crafted web content or HTML emails. Successful exploitation could lead to memory corruption, application crashes, or arbitrary code execution within the context of the browser process. The vulnerability is addressed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and Thunderbird versions 149 and 140.9.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 115.34, < 140.9
  • Mozilla web browser Thunderbird < 149, < 140.9

Timeline

  • 2026-03-24: advisory: Mozilla Foundation Security Advisories MFSA2026-20, 2026-21, and 2026-22 released.
  • 2026-03-24: patched

References

Related threats