Buffer overflow in Mozilla Firefox and Firefox for Android - CVE-2026-7324
Published: April 28, 2026
Vulnerability identifier: #VU128411
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-7324
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code on the target system.
Affected software
Mozilla Firefox
Firefox for Android
Mozilla Thunderbird
Firefox for Android
Mozilla Thunderbird
How to mitigate CVE-2026-7324
Install updates from vendor's website.
Mozilla Firefox - update to 150.0.1
Firefox for Android - update to 150.0.1
Mozilla Thunderbird - addressed in versions 140.10.1, 150.0
Firefox for Android - update to 150.0.1
Mozilla Thunderbird - addressed in versions 140.10.1, 150.0