Mozilla Firefox and Thunderbird Memory Safety Vulnerability Allowing Potential Arbitrary Code Execution

Vulnerability

A memory safety vulnerability has been identified in Mozilla Firefox and Thunderbird, specifically in versions prior to 147. This vulnerability arises from memory safety bugs that were present in Firefox 146 and Thunderbird 146. Some of these bugs indicated potential memory corruption, leading to the presumption that, with sufficient effort, they could have been exploited to execute arbitrary code.

Impact

Exploitation of this vulnerability could have allowed for arbitrary code execution.

Remediation

Users can upgrade to Firefox 147 or Thunderbird 147 to address this vulnerability.

Added: Jan 13, 2026, 2:22 PM
Updated: Jan 13, 2026, 3:31 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.4
remediation
7.7
relevance
2.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.