Executive brief
A memory management vulnerability has been identified in the networking component of Mozilla Firefox and Thunderbird. This flaw could allow a malicious website or browser-based content to cause a crash or potentially execute unauthorized commands on a user's system. While Thunderbird is affected, the risk is lower during standard email reading as scripting is disabled by default, but the risk remains in browser-like contexts.
Technical details
A use-after-free (UAF) vulnerability was discovered in the DOM: Networking component of Mozilla's core engine. The flaw occurs when the application continues to use a pointer after the memory it points to has been deallocated, leading to memory corruption. In Firefox, this can be triggered by malicious web content over the network without requiring specific user interaction or privileges. In Thunderbird, the attack surface is limited because JavaScript is disabled in the email reader, though the vulnerability remains reachable in browser-like contexts. Patches have been released across all affected branches, including Firefox 150.0.2 and various ESR versions.
Affected products
- Mozilla Firefox Fixed in 150.0.2
- Mozilla Firefox ESR Fixed in 140.10.2, 115.35.2
- Mozilla Thunderbird Fixed in 150.0.2, 140.10.2
- Red Hat Enterprise Linux 7, 8, 10.0, 10.2
Timeline
- 2026-05-07: advisory: Mozilla Foundation Security Advisory published
- 2026-05-07: patched: Firefox and Firefox ESR updates released
- 2026-05-08: patched: Thunderbird updates released
- 2026-05-19: advisory: Red Hat published security advisory RHSA-2026:19160
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2034352
- https://www.mozilla.org/security/advisories/mfsa2026-40/
- https://www.mozilla.org/security/advisories/mfsa2026-41/
- https://www.mozilla.org/security/advisories/mfsa2026-42/
- https://www.mozilla.org/security/advisories/mfsa2026-43/
- https://www.mozilla.org/security/advisories/mfsa2026-44/
- https://access.redhat.com/errata/RHSA-2026:19160