CVE-2026-0892

9.8

Mozilla · Firefox, Thunderbird

Multiple memory safety vulnerabilities in Mozilla Firefox and Thunderbird could allow an unauthenticated attacker to execute arbitrary code via memory corruption.

Executive summary

Critical memory safety vulnerabilities in Mozilla Firefox and Thunderbird versions prior to 147 present a significant risk of remote code execution.

Vulnerability

This vulnerability consists of multiple memory safety bugs that, if triggered, allow for memory corruption. Successful exploitation by an unauthenticated attacker could result in arbitrary code execution on the host system.

Business impact

The potential for remote code execution poses a severe threat to data integrity, confidentiality, and overall system security. Given the CVSS score of 9.8, these flaws are classified as critical, as they allow full system compromise without requiring user interaction or authentication.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 147 or later immediately.

Proactive Monitoring: Review endpoint security logs for unusual process spawns or unexpected crashes in the browser or email client processes.

Compensating Controls: Ensure that browser-based security features like sandboxing are fully enabled and that the organization adheres to the principle of least privilege for local user accounts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of these memory safety issues cannot be overstated. Organizations must prioritize the deployment of the 147 updates across all endpoints to mitigate the risk of remote code execution.

More Mozilla CVEs