Executive brief
Mozilla Firefox and Thunderbird are popular open-source web browsers and email clients. Multiple memory safety vulnerabilities were identified that could potentially allow an attacker to corrupt the application's memory. If successfully exploited, these flaws could lead to a service crash or the execution of unauthorized code, though the risk is lower in Thunderbird when reading standard emails as scripting is disabled by default.
Technical details
This advisory addresses multiple memory safety bugs (CWE-119, CWE-787) in the Mozilla codebase used by Firefox and Thunderbird. The vulnerabilities stem from improper restriction of operations within memory buffer bounds, leading to memory corruption. An attacker could potentially exploit these flaws via a network vector to achieve arbitrary code execution. While Thunderbird is affected, the attack surface is mitigated during standard email viewing because JavaScript is disabled; however, risks remain in browser-like contexts. Patches are available in Firefox 150.0.1, Firefox ESR 140.10.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
Affected products
- Mozilla Thunderbird 150.0.0
- Mozilla Thunderbird ESR 140.10.0
- Mozilla Firefox 150.0.0
- Mozilla Firefox ESR 140.10.0
Timeline
- 2026-04-28: disclosed
- 2026-04-28: patched: Fixed in Firefox 150.0.1 and Firefox ESR 140.10.1
- 2026-04-30: patched: Fixed in Thunderbird 150.0.1 and Thunderbird 140.10.1
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2028537%2C2029911%2C2031121%2C2033602
- https://www.mozilla.org/security/advisories/mfsa2026-35/
- https://www.mozilla.org/security/advisories/mfsa2026-36/
- https://www.mozilla.org/security/advisories/mfsa2026-38/
- https://www.mozilla.org/security/advisories/mfsa2026-39/
- https://access.redhat.com/errata/RHSA-2026:19153
- https://access.redhat.com/errata/RHSA-2026:19157