Executive brief
A vulnerability exists in the WebRTC component of Mozilla Firefox and Thunderbird, which is used for real-time communication like video calls and voice chat. An attacker could exploit this flaw to potentially cause memory corruption or gain unauthorized access to information. This could lead to application crashes or the compromise of user data during browser or email client usage.
Technical details
The vulnerability is characterized as an 'Incorrect Boundary Condition' (CWE-119/CWE-131) within the WebRTC component of Mozilla browsers and email clients. It stems from improper restriction of operations within the bounds of a memory buffer or incorrect calculation of buffer sizes. A remote attacker could potentially exploit this over the network without user interaction to achieve memory corruption, which may lead to arbitrary code execution or information disclosure. The issue has been addressed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Affected products
- Mozilla Firefox < 150
- Mozilla Firefox ESR < 115.35, < 140.10
- Mozilla Thunderbird < 150, < 140.10
- Red Hat Enterprise Linux Server (v. 7 ELS)
Timeline
- 2026-04-21: disclosed
- 2026-04-21: patched
- 2026-04-21: advisory
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2027499
- https://www.mozilla.org/security/advisories/mfsa2026-30/
- https://www.mozilla.org/security/advisories/mfsa2026-31/
- https://www.mozilla.org/security/advisories/mfsa2026-32/
- https://www.mozilla.org/security/advisories/mfsa2026-33/
- https://www.mozilla.org/security/advisories/mfsa2026-34/
- https://access.redhat.com/errata/RHSA-2026:10757