Executive brief
Firefox and Thunderbird's HTTP networking component contains an incorrect boundary conditions vulnerability that could allow attackers to cause memory corruption. This could lead to browser crashes or potentially enable attackers to execute arbitrary code with browser privileges, affecting user data integrity and system security.
Technical details
The vulnerability is a boundary condition error in the Networking: HTTP component of Firefox and Thunderbird. Boundary condition flaws occur when code fails to properly validate input lengths or array bounds, potentially leading to out-of-bounds memory access. The flaw was patched in Firefox 156 and Thunderbird 156. The reported CVSS score of 9.8 indicates network-exploitable code execution risk. No public information indicates active exploitation in the wild at time of publication.
Affected products
- Mozilla Firefox before 156
- Mozilla Thunderbird before 156
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156