CVE-2026-4713
7.5Mozilla · Firefox, Thunderbird
Incorrect boundary conditions in the Graphics component of Mozilla Firefox and Thunderbird may lead to a denial of service.
Executive summary
A critical vulnerability involving incorrect boundary conditions in the Graphics component of Mozilla Firefox and Thunderbird allows for potential application instability.
Vulnerability
The flaw exists due to incorrect boundary conditions within the Graphics component, which can be triggered by an unauthenticated attacker to cause a denial of service.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high level of concern regarding system availability. A successful exploit can cause the application to crash, resulting in service disruption for end users and potential loss of productivity or unsaved work.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 149 or later, or to the ESR 140.9 release, to apply the necessary security patches.
Proactive Monitoring: Review application crash logs and system event logs for unusual patterns that may indicate repeated attempts to trigger the graphics rendering flaw.
Compensating Controls: While no direct WAF mitigation applies to this client-side rendering issue, maintaining an updated browser environment and restricting unauthorized software execution remains a primary defense.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the widespread usage of these applications, administrators should prioritize the deployment of the provided patches across all workstations and servers. Applying these updates is the only effective way to prevent potential denial of service attacks targeting the graphics subsystem.
More Mozilla CVEs
Sources
Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.