CVE-2026-4694
7.5Mozilla · Firefox, Thunderbird
An integer overflow vulnerability in the Graphics component of Mozilla Firefox and Thunderbird allows for potential denial of service via incorrect boundary conditions.
Executive summary
A critical integer overflow vulnerability in the Graphics component of Mozilla Firefox and Thunderbird poses a significant risk of service disruption.
Vulnerability
The flaw involves incorrect boundary conditions leading to an integer overflow within the Graphics component. Based on the CVSS vector, this vulnerability is exploitable by an unauthenticated attacker over the network without requiring user interaction.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity level primarily due to its potential to cause system instability or application crashes (Denial of Service). Successful exploitation could result in significant downtime for end users and operational disruption, particularly in enterprise environments that rely on these applications for daily communication and web access.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to the identified fixed versions: Firefox 149, Firefox ESR 115.34 or 140.9, and Thunderbird 149 or 140.9.
Proactive Monitoring: Monitor system logs for repeated application crashes or unexpected service restarts involving the graphics processing modules of these browsers.
Compensating Controls: While no direct virtual patch exists for this memory-related flaw, ensure that end user workstations are running with the principle of least privilege to limit the impact of potential application crashes.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for remote, unauthenticated exploitation, organizations should prioritize the deployment of the provided security updates. Patching the affected software versions is the only definitive method to eliminate the risk of service disruption associated with this integer overflow vulnerability.
More Mozilla CVEs
Sources
Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.