Memory Safety Bugs in Firefox from Mozilla
CVE-2026-8973

8.8HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 May 2026

What is CVE-2026-8973?

Mozilla's Firefox 150 exhibited multiple memory safety issues that raised concerns of memory corruption. While the specific scenarios of exploitation were not fully detailed, it's believed that these issues could potentially be manipulated to execute arbitrary code. The flaws were addressed and resolved in Firefox 151, underscoring the importance of keeping software updated to mitigate such risks.

Affected Version(s)

Firefox 151

Thunderbird 151

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Creskey, Andrew Osmond, Dana Keeler, Henri Sivonen, Jed Davis, John Schanck, Jon Coppeard, Justin Link, Michael Froman, Nika Layzell, Noah Lokocz, Randell Jesup, Steve Fink, Tom Schuster and the Mozilla Fuzzing Team
.