CVE-2026-4718

8.1

Mozilla · Firefox, Thunderbird

An undefined behavior vulnerability exists within the WebRTC signaling component of Mozilla Firefox and Thunderbird, potentially allowing unauthorized data access or integrity compromise.

Executive summary

Mozilla Firefox and Thunderbird contain an undefined behavior flaw in the WebRTC signaling component that requires immediate patching to prevent unauthorized data access.

Vulnerability

This is an undefined behavior vulnerability located in the WebRTC signaling component. Based on the CVSS vector (AV:N/AC:L/PR:N/UI:R), this flaw can be triggered by an unauthenticated remote attacker through a crafted interaction requiring user interaction.

Business impact

The vulnerability carries a CVSS score of 8.1, indicating a high severity risk to the confidentiality and integrity of user data. Exploitation could allow an attacker to bypass security controls, leading to unauthorized information disclosure or modification within the browser or email client environment. Such incidents pose significant risks to organizational data privacy and user trust.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 149 or 140.9 (ESR) or later to resolve the underlying undefined behavior.

Proactive Monitoring: Monitor browser and email client logs for unusual signaling patterns or unexpected crashes related to WebRTC processes.

Compensating Controls: Ensure that users are educated on the risks of interacting with untrusted web content or suspicious email attachments that may attempt to trigger WebRTC signaling vulnerabilities.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the prevalence of Firefox and Thunderbird within enterprise environments, organizations should prioritize the deployment of these security updates. Failure to patch may expose workstations to remote exploitation, potentially leading to a breach of sensitive communications or credentials. Please verify that automatic updates are enabled or push the latest version via your centralized deployment management software immediately.

More Mozilla CVEs

Sources

Originally found and disclosed by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using C, per the CVE Program record.