CVE-2026-4707
7.5Mozilla · Firefox, Thunderbird
A vulnerability in the Graphics: Canvas2D component involves incorrect boundary conditions, which can lead to application instability or denial of service.
Executive summary
A critical boundary condition flaw in the Mozilla Firefox and Thunderbird Graphics: Canvas2D component allows unauthenticated attackers to cause a denial of service.
Vulnerability
The vulnerability stems from improper handling of boundary conditions within the Graphics: Canvas2D component. This flaw is exploitable by an unauthenticated remote attacker through crafted content processed by the browser or email client.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high risk of service disruption. Successful exploitation allows an attacker to trigger an application crash, resulting in denial of service for end users. This can significantly impact productivity and business continuity, especially in organizations that rely heavily on these applications for daily communications and web-based workflows.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 149 or the specified ESR versions (115.34 or 140.9) immediately to resolve the boundary condition flaw.
Proactive Monitoring: Monitor system logs for recurring application crashes or unexpected terminations related to the rendering engine.
Compensating Controls: While no specific virtual patch exists, maintaining updated antivirus software and using browser security policies to restrict untrusted content can reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the ease of exploitability (CVSS vector AV:N/AC:L/PR:N), organizations should prioritize patching all endpoints running the affected versions of Firefox and Thunderbird. Administrators must ensure that automated update mechanisms are functioning correctly to deploy these security fixes across the enterprise environment without delay.
More Mozilla CVEs
Sources
Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.