Memory safety bug in Firefox <149.0.2 & Thunderbird 149.0.1
CVE-2026-5735 Published on April 7, 2026
Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
Vulnerability Analysis
CVE-2026-5735 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Products Associated with CVE-2026-5735
stack.watch emails you whenever new vulnerabilities are published in Mozilla Firefox or Mozilla Thunderbird. Just hit a watch button to start following.
Affected Versions
Mozilla Firefox:- Version 149.0.2, <= * is unaffected.
- Version 149.0.2, <= * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.