
[CIVN-2026-0053] Multiple Vulnerabilities in Mozilla Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Mozilla Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Mozilla Firefox versions prior to 147.0.2
Mozilla Thunderbird versions prior to 140.7.1
Mozilla Thunderbird versions prior to 147.0.1
Overview
Multiple vulnerabilities have been reported in Mozilla products which could be exploited by a remote attacker to execute arbitrary code on the targeted system.
Target Audience:
All end-user organizations and individuals using Mozilla Products.
Risk Assessment:
High risk of compromise and service disruptions.
Impact Assessment:
Potential for system compromise and service unavailability.
Description
Multiple vulnerabilities exist in Mozilla products due to Mitigation bypass in the Privacy: Anti-Tracking component; Use-after-free in the Layout: Scrolling and Overflow component; CSS-based exfiltration of the content from partially encrypted emails when allowing remote content. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-06/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-07/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-08/
References
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2026-06/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-07/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-08/
CVE Name
CVE-2026-24868
CVE-2026-24869
CVE-2026-0818
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAml8m+MACgkQ3jCgcSdc
ys+veRAAmST9IXkpSnUD5NvF9SZfkJ6dyVlDhF97jsmlpNzL/fLD11E9hp4YLyXT
m6mndcQeU6fiGs82G0tVv6VUKK4ZRJmvHlbIrt+d4cI2qL1rbEhI7p3N3Dqj9Uvd
lW8Nalx10lStXFIzeYwVwYY8jTOkMPg+3BRKyTwnKuHDOLn6wCrnuQTJYMvijkTa
IQ6N5XqEAW1SpMUH/NUlMIUZe3BXbEkOBbg9egAJW1GbrClAdVQPI/36Bd/DDIcS
8Yzdklby64Rzjyshvtl46SaaQi6pLZzNZCKv8fhr9AasgEBvo4IPeePDJxaE7aRM
9vrSJOZ18AemvLgE9ZN6gIResy/8gTFO3JAycYnDuo8iW8Qn+zke6PNrIjU8xaaR
89AUVIM5bAHiiAGVX/c1iP2ffNGkk9r2QdJzVU46/ueI1rxMgIZDcDey26U4kCEU
erYSFBQSBjJ4A2lTsyEVcvArBUsYlAD/xPlFIFIcOQ9WMjnefbRwE+YfWAtaM7h7
VtnWz/rCD30Xhtg4lfrRhQQ64JJqDsunqft5DvpvzAyqQbkmbNkjPpPlNEGzOGe2
3tztaOst9UKK+8w0GUxg4F5ZRihLZu+jKWNnMiPUCAkRkOqV5ZYtijp+X7QZnmAo
tDoNOf3DPREFAleC1zi6he99DdUOoj6SSpJ13d0JuIMP8oO6bCs=
=+oaK
—–END PGP SIGNATURE—–


