Junglewise Threat Intelligence

CVE-2026-8093: Mozilla Firefox and Thunderbird memory safety bugs

CVE-2026-8093 · Severity: high · CVSS 8.1 · Published 2026-05-07

Technologies: Mozilla Thunderbird, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are affected by multiple memory safety issues that could allow an attacker to take control of a user's system. These vulnerabilities occur when the software incorrectly handles data in its memory, potentially leading to crashes or the execution of unauthorized commands. For Firefox users, this risk is present when visiting malicious websites, while Thunderbird users are primarily at risk when using browser-like features within the application.

Technical details

This advisory covers a collection of memory safety vulnerabilities (CWE-119) identified in Mozilla Firefox and Thunderbird. The root cause involves improper restriction of operations within the bounds of a memory buffer, leading to evidence of memory corruption. While the attack complexity is rated as high, a remote attacker could potentially exploit these flaws to achieve arbitrary code execution. In Thunderbird, the risk is mitigated during standard email reading because scripting is disabled, but remains a threat in browser-like contexts. The issues are resolved in version 150.0.2 of both products.

Affected products

  • Mozilla Firefox 150.0.1
  • Mozilla Thunderbird 150.0.1

Timeline

  • 2026-05-07: disclosed
  • 2026-05-07: patched: Fixed in Firefox 150.0.2
  • 2026-05-08: patched: Fixed in Thunderbird 150.0.2

References

Related threats