Executive brief
Firefox and Thunderbird contain a security mitigation bypass vulnerability in the JavaScript garbage collector component. An attacker could exploit this flaw to circumvent browser security protections, potentially leading to arbitrary code execution or unauthorized access to user data. The issue affects millions of users of these widely-deployed applications.
Technical details
A mitigation bypass vulnerability exists in the JavaScript: GC (garbage collection) component of Firefox and Thunderbird. The flaw allows an attacker to circumvent existing security mitigations designed to protect against memory corruption attacks. While the exact attack vector and preconditions are not detailed in the available documentation, the vulnerability is classified as high impact and was likely reachable through malicious web content or local attack vectors. Mozilla has patched the issue in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 153.1
- Mozilla Thunderbird before 154
- Mozilla Thunderbird before 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1