CVE-2026-4684

7.5

Mozilla · Firefox, Thunderbird

A race condition leading to a use-after-free vulnerability exists in the Graphics: WebRender component of Mozilla Firefox and Thunderbird, potentially allowing arbitrary code execution.

Executive summary

A critical use-after-free vulnerability in the Mozilla Graphics: WebRender component could allow an unauthenticated remote attacker to execute arbitrary code via a specially crafted web page.

Vulnerability

The vulnerability is a race condition resulting in a use-after-free error within the Graphics: WebRender component. It requires no authentication to trigger, though it typically requires user interaction to visit a malicious site.

Business impact

Successful exploitation of this use-after-free vulnerability can lead to remote code execution, which grants an attacker the ability to compromise the confidentiality, integrity, and availability of the affected system. With a CVSS score of 7.5, this flaw is considered High severity, as it poses a significant risk to organizational endpoints by potentially enabling full system control or the installation of persistent malware.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Mozilla Thunderbird to the latest versions, specifically ensuring the use of versions 149 or the specified ESR releases (115.34 or 140.9) to incorporate the security fix.

Proactive Monitoring: Monitor endpoint crash logs and security event logs for recurring memory-related errors or suspicious browser behavior that may indicate an exploitation attempt.

Compensating Controls: Deploy endpoint protection solutions that can detect unauthorized memory access or shellcode execution, as these may block the exploitation of use-after-free conditions.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

The risk posed by this vulnerability is significant, particularly in environments where users frequently navigate to untrusted web content. Organizations should prioritize the deployment of the provided security updates across all workstations and servers running the affected Mozilla products to eliminate this exposure immediately.

More Mozilla CVEs

Sources

Originally found and disclosed by Oskar L, per the CVE Program record.