CVE 8.1 HIGH

Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147_CVE-2026-0891

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.

Basic Information

ID CVE-2026-0891
Source mozilla
Published Jan 13, 2026 at 13:30
Modified Jan 13, 2026 at 14:33

Affected Product

Vendor Mozilla
Product Firefox
Version unspecified
Affected Versions Mozilla Firefox unspecified
Mozilla Firefox ESR unspecified

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.