Executive brief
Mozilla Firefox and Thunderbird are affected by multiple memory safety vulnerabilities that could allow an attacker to corrupt the application's memory. In practice, a successful exploit could allow an attacker to take control of the affected system or execute unauthorized commands. Users should update to the latest versions of these applications to protect their data and systems from potential compromise.
Technical details
Mozilla developers and community members reported multiple memory safety bugs across various versions of Firefox and Thunderbird. These vulnerabilities include issues such as buffer overflows (CWE-120) and expired pointer dereferences (CWE-825). An attacker could potentially exploit these flaws by tricking a user into visiting a malicious website or processing specially crafted content, leading to memory corruption. Mozilla presumes that with sufficient effort, some of these bugs could be leveraged to achieve arbitrary code execution. The issues are resolved in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Affected products
- Mozilla Firefox ESR < 115.34
- Mozilla Firefox ESR < 140.9
- Mozilla Firefox < 149
- Mozilla Thunderbird ESR < 140.9
- Mozilla Thunderbird < 149
Timeline
- 2026-03-24: advisory
- 2026-03-24: patched
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2013762%2C2015291%2C2016591%2C2016661%2C2016664%2C2017303%2C2017894%2C2018090%2C2018196%2C2018379%2C2019112%2C2022090%2C2022243%2C2022351%2C2022478%2C2022676
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-21/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930