Mozilla · Thunderbird · CVE-2026-5735
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 149.0.2
Thunderbird versions prior to 149.0.2
Description
Memory safety bugs exist in Firefox 149.0.1 and Thunderbird 149.0.1. These bugs demonstrate evidence of memory corruption, and it is presumed that, with sufficient effort, they could be exploited to execute arbitrary code. The vulnerability involves writing beyond buffer boundaries.
Recommendations
Update Firefox to version 149.0.2 or later.
Update Thunderbird to version 149.0.2 or later.