Memory Safety Bugs in Mozilla Products Affecting Firefox and Thunderbird
CVE-2026-4720

9.8CRITICAL

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
24 March 2026

What is CVE-2026-4720?

Recent findings indicate the presence of memory safety bugs in specific versions of Firefox and Thunderbird, which have raised alarm due to potential memory corruption. Versions prior to Firefox 149 and Thunderbird 149, as well as Firefox ESR versions before 140.9, are vulnerable. If exploited, these memory corruption issues could allow an attacker to execute arbitrary code, highlighting the importance of timely updates and robust security measures.

Affected Version(s)

Firefox < 149

Firefox ESR < 140.9

Thunderbird < 149

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Holler, Gabriele Svelto, Tom Schuster and the Mozilla Fuzzing Team
.