Junglewise Threat Intelligence

CVE-2026-8092: Mozilla Firefox and Thunderbird memory safety bugs

CVE-2026-8092 · Severity: high · CVSS 8.1 · Published 2026-05-07

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular web browser and email applications. Multiple memory safety vulnerabilities were discovered that could allow an attacker to corrupt the application's memory. If successfully exploited, these flaws could allow an attacker to take control of a user's computer or run unauthorized software.

Technical details

This advisory covers a collection of memory safety bugs (including out-of-bounds reads, out-of-bounds writes, and use-after-free vulnerabilities) identified through fuzzing and internal security audits. These flaws exist in the core engine of Firefox and Thunderbird. An attacker could potentially exploit these vulnerabilities by enticing a user to visit a malicious website or interact with malicious content, leading to memory corruption. Mozilla presumes that with sufficient effort, some of these bugs could be leveraged for arbitrary code execution. The issues are fixed in Firefox 150.0.2, Firefox ESR 140.10.2, Firefox ESR 115.35.2, Thunderbird 150.0.2, and Thunderbird 140.10.2.

Affected products

  • Mozilla Firefox 150.0.1
  • Mozilla Firefox ESR 115.35.1, 140.10.1
  • Mozilla Thunderbird 150.0.1
  • Mozilla Thunderbird ESR 140.10.1

Timeline

  • 2026-05-07: disclosed
  • 2026-05-07: patched
  • 2026-05-07: advisory

References

Related threats