CVE-2026-4704
7.5Mozilla · Firefox, Thunderbird
A denial-of-service vulnerability exists in the WebRTC signaling component of Mozilla Firefox and Thunderbird, allowing remote attackers to crash the application.
Executive summary
A critical denial-of-service vulnerability in the WebRTC signaling component of Mozilla Firefox and Thunderbird exposes users to potential application crashes.
Vulnerability
The flaw resides within the WebRTC signaling component. It is an unauthenticated, network-based vulnerability that can be triggered remotely without user interaction.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a high severity due to its potential to disrupt business operations. Successful exploitation results in a denial-of-service, which can cause significant downtime for users relying on these applications for communication and web-based tasks. The ease of remote exploitation makes this an urgent concern for organizations deploying these browsers.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 149 or 140.9, as these releases contain the necessary security fixes.
Proactive Monitoring: Review application crash logs and network security traffic for unusual patterns originating from WebRTC signaling processes.
Compensating Controls: If immediate patching is not feasible, restrict network access to untrusted WebRTC endpoints and ensure that endpoint security solutions are configured to monitor for process instability.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high impact of a denial-of-service condition, IT administrators should prioritize the deployment of the provided patches across all enterprise workstations. Ensure that automated update mechanisms are enabled for Firefox and Thunderbird to maintain compliance with the latest security baseline and prevent service disruption.
More Mozilla CVEs
Sources
Originally found and disclosed by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using C, per the CVE Program record.