Mozilla Patches Firefox, Thunderbird Code Execution Flaws
Mozilla fixed multiple vulnerabilities in Firefox and Thunderbird, including memory safety bugs that could allow arbitrary code execution.
Mozilla has disclosed and patched several vulnerabilities affecting Firefox and Thunderbird, the most severe of which could enable arbitrary code execution if exploited. The flaws include a denial-of-service issue triggered via a malicious LDAP address-book server, a chat UI manipulation vulnerability through injection, and memory safety bugs resolved in Firefox 152.0.4. Successful exploitation could allow an attacker to install programs, manipulate or delete data, or create new accounts with full user rights, with impact scaled by the privilege level of the affected user account.
No evidence of in-the-wild exploitation has been reported at this time. Affected versions include Firefox prior to 152.0.4, Thunderbird prior to 152.0.1, and Thunderbird prior to 140.12.1. MS-ISAC recommends prompt patching, least-privilege configurations, exploit protection features, and web/email content restrictions to mitigate risk pending update deployment.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-mozilla-products-could-allow-for-arbitrary-code-execution_2026-065
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free