CVE-2026-4718
8.1Mozilla · Firefox, Thunderbird
An undefined behavior vulnerability exists within the WebRTC signaling component of Mozilla Firefox and Thunderbird, potentially allowing unauthorized data access or integrity compromise.
Executive summary
Mozilla Firefox and Thunderbird contain an undefined behavior flaw in the WebRTC signaling component that requires immediate patching to prevent unauthorized data access.
Vulnerability
This is an undefined behavior vulnerability located in the WebRTC signaling component. Based on the CVSS vector (AV:N/AC:L/PR:N/UI:R), this flaw can be triggered by an unauthenticated remote attacker through a crafted interaction requiring user interaction.
Business impact
The vulnerability carries a CVSS score of 8.1, indicating a high severity risk to the confidentiality and integrity of user data. Exploitation could allow an attacker to bypass security controls, leading to unauthorized information disclosure or modification within the browser or email client environment. Such incidents pose significant risks to organizational data privacy and user trust.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 149 or 140.9 (ESR) or later to resolve the underlying undefined behavior.
Proactive Monitoring: Monitor browser and email client logs for unusual signaling patterns or unexpected crashes related to WebRTC processes.
Compensating Controls: Ensure that users are educated on the risks of interacting with untrusted web content or suspicious email attachments that may attempt to trigger WebRTC signaling vulnerabilities.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the prevalence of Firefox and Thunderbird within enterprise environments, organizations should prioritize the deployment of these security updates. Failure to patch may expose workstations to remote exploitation, potentially leading to a breach of sensitive communications or credentials. Please verify that automatic updates are enabled or push the latest version via your centralized deployment management software immediately.
More Mozilla CVEs
Sources
Originally found and disclosed by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using C, per the CVE Program record.