Executive brief
Firefox and Thunderbird contain a use-after-free vulnerability in the graphics text rendering component that could allow attackers to crash the application or potentially execute arbitrary code. This affects web browsing and email clients used by millions of users, risking availability and system compromise if exploited.
Technical details
A use-after-free vulnerability exists in the Graphics: Text component of Firefox and Thunderbird, a memory safety defect where freed memory is accessed after deallocation. The vulnerability is reachable via normal browsing or email viewing without additional authentication or special preconditions. Successful exploitation could lead to application crash (denial of service) or remote code execution depending on the attacker's ability to control heap layout. The vulnerability has been fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird ESR before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3