Executive brief
Mozilla Firefox and Thunderbird are popular web browsing and email applications. Multiple memory safety issues were discovered that could allow an attacker to potentially execute malicious code on a user's system. While these risks are lower when reading standard emails in Thunderbird, they pose a significant threat in browser-like contexts or when interacting with malicious web content.
Technical details
This advisory covers multiple memory safety bugs (CWE-119) identified by the Mozilla Fuzzing Team in Firefox 150.0.0 and Thunderbird 150.0.0. These vulnerabilities involve improper restriction of operations within the bounds of a memory buffer, which can lead to memory corruption. An attacker could potentially leverage these flaws to achieve arbitrary code execution. In Thunderbird, the risk is mitigated during standard email reading because scripting is disabled, but the application remains vulnerable in browser-like contexts. The issues have been resolved in Firefox 150.0.1 and Thunderbird 150.0.1.
Affected products
- Mozilla Firefox 150.0.0
- Mozilla Thunderbird 150.0.0
Timeline
- 2026-04-28: disclosed
- 2026-04-28: patched: Fixed in Firefox 150.0.1
- 2026-04-30: patched: Fixed in Thunderbird 150.0.1
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029419%2C2029717%2C2029769%2C2029886
- https://www.mozilla.org/security/advisories/mfsa2026-35/
- https://www.mozilla.org/security/advisories/mfsa2026-38/
- https://access.redhat.com/security/cve/CVE-2026-7324
- https://bugzilla.redhat.com/show_bug.cgi?id=2463482
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7324.json