CVE-2026-2801
7.5Mozilla · Firefox, Thunderbird
A boundary condition error exists in the JavaScript WebAssembly component of Mozilla Firefox and Thunderbird, potentially leading to a denial of service.
Executive summary
A critical boundary condition vulnerability in the JavaScript WebAssembly component of Mozilla Firefox and Thunderbird allows for potential service disruption.
Vulnerability
This vulnerability involves incorrect boundary conditions within the WebAssembly implementation of the JavaScript engine. It is an unauthenticated vulnerability that can be triggered remotely without user interaction.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation could lead to an application crash or denial of service, which disrupts critical business workflows relying on these browsers or email clients. The lack of required user interaction makes this particularly dangerous for remote exploitation.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 148 or later to incorporate the vendor security fixes.
Proactive Monitoring: Monitor system logs for repeated application crashes or unexpected terminations of the browser or email client processes.
Compensating Controls: Ensure that endpoint security solutions are updated to detect and block malicious web content that may attempt to leverage WebAssembly vulnerabilities.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS severity and the potential for remote, unauthenticated exploitation, administrators should prioritize patching. Deploy the update to version 148 across all enterprise endpoints immediately to eliminate the risk of service disruption.
More Mozilla CVEs
Sources
Originally found and disclosed by Kanaru Sato, per the CVE Program record.