CVE-2026-5735: Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2
Published Apr 7, 2026
·Updated
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<149.0.2
149.0.2
Mozilla Firefox<149.0.2
Mozilla Thunderbird<149.0.2
Mozilla Thunderbird<149.0.2
149.0.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.2 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 149.0.2 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 149.0.2
Event History
Apr 7, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
Updated
via Mozilla·12:00 AM
Affected Software
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
Description
Data Sourced
via Red Hat·01:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.