CVE-2026-0892: Memory safety bugs fixed in Firefox 147 and Thunderbird 147
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0892?
CVE-2026-0892 has a severity rating that indicates the potential for memory corruption and possible arbitrary code execution.
How do I fix CVE-2026-0892?
To mitigate CVE-2026-0892, users should update to Mozilla Firefox version 147 or Thunderbird version 147.
What products are affected by CVE-2026-0892?
CVE-2026-0892 affects Mozilla Firefox version 146 and earlier, as well as Thunderbird version 146 and earlier.
What type of vulnerability is CVE-2026-0892?
CVE-2026-0892 is classified as a memory safety vulnerability that could lead to memory corruption.
Is CVE-2026-0892 actively being exploited?
While there is evidence of potential exploitation, it is not confirmed if CVE-2026-0892 is being actively exploited in the wild.