CVE-2026-4685

7.5

Mozilla · Firefox and Thunderbird

A vulnerability in the Graphics: Canvas2D component involves incorrect boundary conditions, potentially leading to a denial of service.

Executive summary

Mozilla has addressed a critical boundary condition vulnerability in the Graphics: Canvas2D component of Firefox and Thunderbird that could allow for application crashes.

Vulnerability

The flaw exists within the Graphics: Canvas2D component, where incorrect boundary conditions occur during rendering operations. This is an unauthenticated vulnerability that allows an attacker to trigger a denial of service condition.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which can cause significant disruption to user productivity and business continuity. With a CVSS score of 7.5, the vulnerability is classified as High severity because the flaw is remotely exploitable and does not require user interaction or authentication to trigger, posing a risk to organizational uptime.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to the specified fixed versions, which are Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9, or later.

Proactive Monitoring: Monitor system logs for repeated application crashes or unexpected service restarts that may indicate attempted exploitation of the Canvas2D rendering engine.

Compensating Controls: While there are no direct virtual patches for this internal rendering flaw, ensure that endpoints are protected by robust endpoint security solutions that can detect and isolate anomalous process behavior.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the High severity rating and the potential for remote exploitation, it is imperative that IT administrators prioritize the deployment of the provided security updates. Patching these browsers promptly remains the most effective defense against potential service disruption and potential follow-on exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.