Mozilla Firefox and Thunderbird Memory Safety Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability has been identified in Mozilla Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147, and Thunderbird 147. This vulnerability arises from memory safety issues that could potentially be exploited to execute arbitrary code. Evidence of memory corruption was observed, suggesting that, with sufficient effort, these issues could be exploited.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution.

Remediation

Users can upgrade to Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148, or Thunderbird 148 to address this vulnerability.

Added: Feb 24, 2026, 2:37 PM
Updated: Feb 24, 2026, 10:38 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.6
remediation
7.7
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.