Executive brief
Firefox and Thunderbird contain a memory safety vulnerability in the DOM rendering engine that can lead to memory corruption when processing malicious web content. An attacker can exploit this flaw by hosting a specially crafted webpage; when a user visits the site, the vulnerability could enable arbitrary code execution or cause the application to crash, affecting user data and device security.
Technical details
This is a use-after-free vulnerability in the DOM: Core & HTML component, where freed memory is accessed after deallocation, potentially leading to memory corruption. The vulnerability is triggered during DOM manipulation and can be reached through network-delivered web content without requiring user authentication or special browser configuration. A successful exploit could allow arbitrary code execution within the browser's security context. The vulnerability was patched in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
Affected products
- Mozilla Firefox before 155
- Mozilla Firefox ESR before 153.2
- Mozilla Thunderbird before 155
- Mozilla Thunderbird ESR before 153.2
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2