Executive brief
Firefox and Thunderbird contain a use-after-free vulnerability in their WebAssembly JavaScript engine component. An attacker could exploit this memory safety flaw through malicious JavaScript code to potentially achieve remote code execution or crash the browser. This vulnerability affects users of Firefox and Thunderbird versions prior to 156.
Technical details
A use-after-free vulnerability exists in the JavaScript: WebAssembly component of Firefox and Thunderbird. The vulnerability occurs when freed memory is accessed after deallocation, potentially allowing an attacker to read sensitive data or execute arbitrary code. The flaw is reachable through network-delivered JavaScript/WebAssembly code without requiring user authentication beyond visiting a malicious website. Mozilla has patched this issue in Firefox 156 and Thunderbird 156. The CVSS score of 8.8 indicates high severity with potential for significant impact.
Affected products
- Mozilla Firefox before 156
- Mozilla Thunderbird before 156
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156