Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
The vulnerability results from the use of uninitialized memory (CWE-908, CWE-457) in the Graphics: Text component. When the application reads data from memory areas that were not properly initialized before use, an attacker can potentially access sensitive data stored in that memory or cause unstable application behavior. The attack vector is network-based, requires no privileges or user interaction, which significantly increases the risk of exploitation.
An attacker can remotely access sensitive data stored in uninitialized memory areas (breach of confidentiality) and cause application unavailability (breach of availability).
Mozilla Firefox should be updated to version 148 or later and Mozilla Thunderbird to version 148 or later. Patches are available through the vendor's automatic update mechanism and in the references at mfsa2026-13 and mfsa2026-16.
Mozilla Firefox versions prior to 148 and Mozilla Thunderbird versions prior to 148.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HMozilla Firefox
APPMozilla< 148.0Mozilla Thunderbird
APPMozilla< 148.0
Related vulnerabilities
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open
RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...