CVE-2026-5732
8.8Mozilla · Firefox, Thunderbird
An integer overflow vulnerability in the Graphics: Text component of Mozilla Firefox and Thunderbird allows for potential memory corruption.
Executive summary
An integer overflow vulnerability in the Graphics: Text component of Mozilla Firefox and Thunderbird poses a high risk of memory corruption and potential arbitrary code execution.
Vulnerability
This flaw stems from incorrect boundary conditions leading to an integer overflow within the Graphics: Text component, which can be triggered by an unauthenticated attacker via specially crafted content.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its potential for total impact on confidentiality, integrity, and availability. Successful exploitation could allow a remote attacker to execute arbitrary code or cause a crash, leading to significant system compromise and potential data breaches within the enterprise environment.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 149.0.2 or 140.9.1 (ESR) immediately to incorporate the vendor security patches.
Proactive Monitoring: Review system logs for unusual application behavior or crash reports that may indicate exploitation attempts against the browser or mail client.
Compensating Controls: Utilize endpoint protection platforms and browser security settings to restrict the execution of untrusted scripts or content while the update deployment is in progress.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
Given the high severity and potential for arbitrary code execution, organizations should prioritize patching these applications across all managed endpoints. Please ensure that internal deployment schedules are accelerated to move affected software to the stated fixed versions immediately, as memory corruption vulnerabilities in core components represent a primary target for malicious actors.
More Mozilla CVEs
Sources
Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.