Executive brief
Mozilla Firefox and Thunderbird were found to contain multiple memory safety vulnerabilities. These flaws could allow an attacker to potentially execute arbitrary code or crash the application if a user visits a malicious website or interacts with specially crafted content. Users should update to version 149 or later to mitigate these risks.
Technical details
Mozilla developers reported several memory safety bugs in Firefox 148 and Thunderbird 148. Some of these vulnerabilities showed evidence of memory corruption, which typically indicates that with sufficient effort, an attacker could achieve remote code execution (RCE). The vulnerabilities are addressed by improving memory handling and boundary checks in the affected components. The issues are resolved in Firefox 149 and Thunderbird 149. While Thunderbird is affected, the risk is lower in email contexts where JavaScript is disabled, but remains high in browser-like contexts.
Affected products
- Mozilla Firefox < 149
- Mozilla Thunderbird < 149
Timeline
- 2026-03-24: disclosed
- 2026-03-24: patched: Fixed in Firefox 149 and Thunderbird 149
- 2026-03-24: advisory
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1944033%2C1997282%2C2009213%2C2011412%2C2021925%2C2022034
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://access.redhat.com/security/cve/CVE-2026-4729
- https://bugzilla.redhat.com/show_bug.cgi?id=2450745
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4729.json