Executive brief
A critical security vulnerability has been identified in the WebRTC component of Mozilla Firefox and Thunderbird, which are widely used for web browsing and email communication. This flaw could allow a remote attacker to execute unauthorized code or gain control over an affected system. While Thunderbird users are generally protected when reading standard emails, the risk remains high in browser-like contexts or if malicious scripts are executed.
Technical details
This vulnerability is classified as a code injection issue (CWE-94) within the WebRTC component of Mozilla products. The flaw allows for improper control of code generation, which can be leveraged by a remote, unauthenticated attacker to execute arbitrary code on the target system. The attack vector is network-based and, according to CISA-ADP, does not require user interaction or elevated privileges, resulting in a CVSS score of 9.8. Mozilla has addressed this in Firefox ESR 140.10.2 and Thunderbird 140.10.2. Red Hat has also released corresponding updates for various Enterprise Linux versions.
Affected products
- Mozilla Firefox ESR < 140.10.2
- Mozilla Thunderbird < 140.10.2
- Red Hat Enterprise Linux 8, 9, 10
Timeline
- 2026-05-07: advisory: Mozilla Foundation Security Advisory 2026-41 published
- 2026-05-07: patched: Fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2
- 2026-05-19: advisory: Red Hat security advisory RHSA-2026:19160 published
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2035939
- https://www.mozilla.org/security/advisories/mfsa2026-41/
- https://www.mozilla.org/security/advisories/mfsa2026-44/
- https://access.redhat.com/errata/RHSA-2026:19160
- https://access.redhat.com/errata/RHSA-2026:20566
- https://access.redhat.com/errata/RHSA-2026:20574
- https://access.redhat.com/errata/RHSA-2026:24508