Executive brief
Mozilla Firefox and Thunderbird are popular web browser and email applications. Multiple memory safety vulnerabilities have been identified that could allow an attacker to crash the application or potentially execute unauthorized code on a user's computer. This could lead to the theft of sensitive data, unauthorized access to accounts, or full system compromise if a user visits a malicious website or interacts with malicious content.
Technical details
Mozilla developers and the fuzzing team identified several memory safety bugs in Firefox and Thunderbird. These vulnerabilities include out-of-bounds writes (CWE-787) and out-of-bounds reads (CWE-125) that exhibit evidence of memory corruption. An attacker could potentially exploit these flaws via a network-based attack vector to achieve arbitrary code execution. While Thunderbird's default configuration disables scripting in emails, reducing the risk, the vulnerabilities remain exploitable in browser-like contexts. The issues are resolved in Firefox 149.0.2 and Thunderbird 149.0.2.
Affected products
- Mozilla Firefox < 149.0.2
- Mozilla Thunderbird < 149.0.2
Timeline
- 2026-04-07: disclosed
- 2026-04-07: patched
- 2026-04-07: advisory
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2025475%2C2025477
- https://www.mozilla.org/security/advisories/mfsa2026-25/
- https://www.mozilla.org/security/advisories/mfsa2026-28/
- https://access.redhat.com/security/cve/CVE-2026-5735
- https://bugzilla.redhat.com/show_bug.cgi?id=2455904
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5735.json