Junglewise Threat Intelligence

CVE-2026-5732: Mozilla Firefox and Thunderbird integer overflow in Graphics: Text component

CVE-2026-5732 · Severity: high · CVSS 8.8 · Published 2026-04-07

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular open-source web browsers and email clients. A vulnerability in the text rendering component could allow an attacker to compromise a user's system if they visit a malicious website or view malicious content in a browser-like context. This could lead to unauthorized access to sensitive data, system instability, or the execution of malicious code.

Technical details

An integer overflow vulnerability exists in the 'Graphics: Text' component of Mozilla browsers and email clients due to incorrect boundary conditions. The flaw is triggered when the application processes specially crafted text content, leading to memory corruption. An attacker can exploit this by enticing a user to visit a malicious webpage or interact with malicious content. While Thunderbird is affected, the risk is lower in email contexts where scripting is disabled, but remains high in browser-like contexts. Successful exploitation could allow for arbitrary code execution or a denial-of-service condition. Patches are available in Firefox 149.0.2, Firefox ESR 140.9.1, and corresponding Thunderbird versions.

Affected products

  • Mozilla Firefox < 149.0.2
  • Mozilla Firefox ESR < 140.9.1
  • Mozilla Thunderbird < 149.0.2
  • Mozilla Thunderbird ESR < 140.9.1

Timeline

  • 2026-04-07: advisory: Mozilla Foundation Security Advisory published
  • 2026-04-07: patched: Fixed in Firefox 149.0.2 and Firefox ESR 140.9.1

References

Related threats