Executive brief
Mozilla Firefox and Thunderbird are popular open-source web browsers and email clients. A vulnerability in the text rendering component could allow an attacker to compromise a user's system if they visit a malicious website or view malicious content in a browser-like context. This could lead to unauthorized access to sensitive data, system instability, or the execution of malicious code.
Technical details
An integer overflow vulnerability exists in the 'Graphics: Text' component of Mozilla browsers and email clients due to incorrect boundary conditions. The flaw is triggered when the application processes specially crafted text content, leading to memory corruption. An attacker can exploit this by enticing a user to visit a malicious webpage or interact with malicious content. While Thunderbird is affected, the risk is lower in email contexts where scripting is disabled, but remains high in browser-like contexts. Successful exploitation could allow for arbitrary code execution or a denial-of-service condition. Patches are available in Firefox 149.0.2, Firefox ESR 140.9.1, and corresponding Thunderbird versions.
Affected products
- Mozilla Firefox < 149.0.2
- Mozilla Firefox ESR < 140.9.1
- Mozilla Thunderbird < 149.0.2
- Mozilla Thunderbird ESR < 140.9.1
Timeline
- 2026-04-07: advisory: Mozilla Foundation Security Advisory published
- 2026-04-07: patched: Fixed in Firefox 149.0.2 and Firefox ESR 140.9.1
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2017867
- https://www.mozilla.org/security/advisories/mfsa2026-25/
- https://www.mozilla.org/security/advisories/mfsa2026-27/
- https://www.mozilla.org/security/advisories/mfsa2026-28/
- https://www.mozilla.org/security/advisories/mfsa2026-29/
- https://access.redhat.com/errata/RHSA-2026:11805
- https://access.redhat.com/errata/RHSA-2026:11813