Buffer overflow in Firefox for Android and Mozilla Firefox - CVE-2026-8973

 

Buffer overflow in Firefox for Android and Mozilla Firefox - CVE-2026-8973

Published: May 19, 2026


Vulnerability identifier: #VU131863
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8973
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can trigger the flaws to execute arbitrary code.

Some of the bugs showed evidence of memory corruption.


Affected software

Firefox for Android
Mozilla Firefox
Mozilla Thunderbird

How to mitigate CVE-2026-8973

Install security update from vendor's website.

Firefox for Android - update to 151.0
Mozilla Firefox - update to 151.0
Mozilla Thunderbird - update to 151.0

External References

Related Security Bulletins