Executive brief
Firefox and Thunderbird contain a use-after-free vulnerability in the networking stack that allows an attacker to crash the application or potentially execute arbitrary code. This affects web browsers used by millions and could be exploited through network-based attacks to compromise user systems or disrupt service availability.
Technical details
A use-after-free vulnerability exists in Mozilla Firefox and Thunderbird's Networking component. The vulnerability stems from improper memory management where previously freed memory is accessed, allowing an attacker to trigger a crash or potentially achieve code execution. Attack requires network connectivity and the victim visiting a malicious webpage or receiving a crafted network packet; no special user privileges are required. An attacker can exploit this to cause denial of service or achieve arbitrary code execution with the privileges of the browser process. Patches are available in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Firefox < 156
- Mozilla Firefox ESR 140.x < 140.16, 153.x < 153.3
- Mozilla Thunderbird < 156
- Mozilla Thunderbird 140.x < 140.16, 153.x < 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, Thunderbird 153.3