Executive brief
Mozilla Firefox and Thunderbird are affected by multiple memory safety vulnerabilities that could allow an attacker to execute malicious code on a user's system. These issues occur when the software incorrectly handles data in memory, potentially leading to system instability or unauthorized access to sensitive information. While Thunderbird is generally less susceptible when reading standard emails, the risk remains high in browser-like contexts or if malicious scripts are executed. Users should update to the latest versions immediately to protect their data and operations.
Technical details
This advisory covers a collection of memory safety bugs (CWE-787, CWE-120) identified by the Mozilla Fuzzing Team and other researchers. The vulnerabilities involve memory corruption issues, including out-of-bounds writes and buffer overflows, within the browser engine. An unauthenticated remote attacker could exploit these flaws by enticing a user to visit a specially crafted website or interact with malicious content, potentially leading to arbitrary code execution (RCE). While Thunderbird disables scripting by default when reading email, the vulnerabilities are exploitable in browser-like contexts. The issues are resolved in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
Affected products
- Mozilla Firefox ESR < 140.9.1
- Mozilla Firefox < 149.0.2
- Mozilla Thunderbird ESR < 140.9.1
- Mozilla Thunderbird < 149.0.2
Timeline
- 2026-04-07: advisory: Mozilla Foundation Security Advisory published
- 2026-04-07: patched: Fixed versions released by Mozilla
- 2026-04-29: advisory: Red Hat security advisory issued for affected packages
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022369%2C2023026%2C2023545%2C2023555%2C2023958%2C2025422%2C2025468%2C2025492%2C2025505
- https://www.mozilla.org/security/advisories/mfsa2026-25/
- https://www.mozilla.org/security/advisories/mfsa2026-27/
- https://www.mozilla.org/security/advisories/mfsa2026-28/
- https://www.mozilla.org/security/advisories/mfsa2026-29/
- https://access.redhat.com/errata/RHSA-2026:11805
- https://access.redhat.com/errata/RHSA-2026:11813