Mozilla Firefox and Thunderbird Memory Safety Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability has been identified in Mozilla Firefox and Thunderbird that arises from memory safety issues. This vulnerability is present in multiple versions, including Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149, and Thunderbird 149. Some of these memory safety bugs showed signs of memory corruption, leading to the presumption that, with sufficient effort, they could be exploited to execute arbitrary code.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution.

Remediation

Users can upgrade to Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, or Thunderbird 140.10 to address this vulnerability.

Added: Apr 26, 2026, 7:57 PM
Updated: Apr 26, 2026, 7:57 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.6
remediation
7.7
relevance
6.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.