CVE-2026-4699
7.5Mozilla · Firefox, Thunderbird
A vulnerability exists in the Layout: Text and Fonts component of Mozilla Firefox and Thunderbird due to incorrect boundary conditions, which can lead to a denial of service.
Executive summary
Mozilla Firefox and Thunderbird are vulnerable to a critical denial of service flaw in their text rendering engine that allows unauthenticated remote attackers to crash the application.
Vulnerability
The vulnerability stems from incorrect boundary conditions within the Layout: Text and Fonts component. An unauthenticated remote attacker can trigger this flaw by providing malicious input, causing the application to crash.
Business impact
The exploitation of this vulnerability results in a denial of service, which can disrupt business operations that rely on these browsers or email clients. Given the CVSS score of 7.5, this is considered a High severity issue, as it is fully automatable and requires no user interaction or authentication to trigger a crash. Widespread disruption of communication and web access tools can lead to significant productivity losses.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to the fixed versions (149 or the specified ESR releases) immediately.
Proactive Monitoring: Monitor system logs for recurring application crashes or unexpected service termination events associated with these software products.
Compensating Controls: While no direct virtual patch exists, ensure that endpoint protection software is updated to detect and block malicious web content that may attempt to exploit known browser rendering vulnerabilities.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a significant risk to organizational availability due to the ease with which it can be triggered remotely. IT administrators should prioritize the deployment of the provided security updates across all workstations and servers running the affected Mozilla products to prevent potential service disruptions.
More Mozilla CVEs
Sources
Originally found and disclosed by Matej Smycka, per the CVE Program record.