Executive brief
Firefox and Thunderbird's JavaScript engine contained a race condition vulnerability that could allow attackers to cause memory safety issues or execute arbitrary code through specially crafted web content. This affects all users of these browsers and email clients until they update to patched versions.
Technical details
A race condition vulnerability exists in Mozilla Firefox and Thunderbird's JavaScript engine component. The vulnerability allows attackers to exploit timing-dependent conditions in the JavaScript execution environment to cause memory safety violations or achieve arbitrary code execution. The attack vector is network-based, requiring only the victim to visit a malicious website or receive a specially crafted email with embedded content. No user interaction beyond normal browsing or email reading is required. Mozilla patched this issue in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Affected products
- Mozilla Firefox below 154
- Mozilla Firefox ESR below 153.1
- Mozilla Thunderbird below 154
- Mozilla Thunderbird ESR below 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1