CVE-2026-7324: Memory safety bugs fixed in Thunderbird 150.0.1
Memory safety bugs present in Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1.
Other sources
Memory safety bugs present in Firefox 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.1 - Upgrade
Upgrade
firefoxto a version that resolves this vulnerability.Fixed in 150.0.1 - Upgrade
Upgrade
thunderbirdto a version that resolves this vulnerability.Fixed in 150.0.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-7324?
CVE-2026-7324 is classified as a significant memory safety vulnerability which could potentially lead to arbitrary code execution.
How do I fix CVE-2026-7324?
To mitigate CVE-2026-7324, you should update Mozilla Firefox or Thunderbird to version 150.0.1 or later.
Which versions of software are affected by CVE-2026-7324?
CVE-2026-7324 affects Mozilla Firefox and Thunderbird version 150.0.0.
What types of problems does CVE-2026-7324 address?
CVE-2026-7324 addresses memory safety issues that can lead to memory corruption.
Is exploiting CVE-2026-7324 easy for attackers?
While the presence of memory corruption vulnerabilities suggests potential exploitation, exploiting CVE-2026-7324 would require substantial effort on the part of attackers.