Executive brief
Firefox and Thunderbird browsers contain a use-after-free vulnerability in the text and font rendering component, which can be triggered when processing malicious web content. An attacker could exploit this to crash the browser or potentially execute arbitrary code, compromising user data and system security.
Technical details
A use-after-free vulnerability exists in the Layout: Text and Fonts component of Firefox and Thunderbird. This vulnerability occurs when memory is accessed after it has been freed, typically during text and font rendering operations. The vulnerability can be triggered remotely via malicious web content without requiring user authentication or special privileges. Successful exploitation could allow an attacker to execute arbitrary code with the privileges of the affected browser process. The vulnerability has been patched in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 115.39, 140.14, and 153.1
- Mozilla Thunderbird before 154, 140.14, and 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Firefox 154, Firefox ESR 115.39, 140.14, 153.1, Thunderbird 154, 140.14, 153.1