Mozilla Firefox and Thunderbird Heap Buffer Overflow Vulnerability in libvpx

Vulnerability

A heap buffer overflow vulnerability has been identified in the libvpx library, affecting multiple versions of Mozilla Firefox and Thunderbird. Specifically, this vulnerability impacts Firefox versions prior to 147.0.4, Firefox ESR versions prior to 140.7.1 and 115.32.1, as well as Thunderbird versions prior to 140.7.2 and 147.0.2.

Impact

Exploitation of this vulnerability leads to a heap buffer overflow, which can commonly result in arbitrary code execution or causing a program to crash.

Remediation

Users can upgrade to Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 147.0.2, or Thunderbird 140.7.2 to address this vulnerability.

Added: Feb 16, 2026, 3:20 PM
Updated: Feb 16, 2026, 4:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.8
remediation
0.0
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.