Junglewise Threat Intelligence

CVE-2026-4696: Mozilla Firefox and Thunderbird use-after-free in Layout Text and Fonts

CVE-2026-4696 · Severity: critical · CVSS 9.8 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A critical vulnerability has been identified in the text and font processing component of Mozilla Firefox and Thunderbird. This flaw could allow an attacker to execute malicious code or crash the application when a user views specially crafted web content or emails. Organizations should update to the latest versions of these applications to protect against potential data theft or system compromise.

Technical details

A use-after-free (UAF) vulnerability was discovered in the 'Layout: Text and Fonts' component of Mozilla browsers and mail clients. The flaw occurs due to improper memory management (CWE-416) when handling text layout, potentially leading to an expired pointer dereference (CWE-825). An attacker can exploit this by enticing a user to visit a malicious website or open a specially crafted email, requiring no special privileges. Successful exploitation could allow for arbitrary code execution within the context of the application or a denial-of-service (DoS) condition. The issue is resolved in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 115.34, < 140.9
  • Mozilla Thunderbird < 149, < 140.9

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: patched
  • 2026-03-24: advisory

References

Related threats