
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2447 is a heap-based buffer overflow vulnerability in libvpx, the open-source VP8/VP9 video codec library, as used in Mozilla Firefox and Thunderbird. Reported by researcher "jayjayjazz" and disclosed on February 16, 2026, it affects Firefox versions prior to 147.0.4, Firefox ESR prior to 140.7.1 and 115.32.1, Thunderbird prior to 147.0.2, and Thunderbird prior to 140.7.2. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Mozilla Advisory, Mozilla Advisory). Oracle Solaris 11.4 is also listed as an affected platform via its bundled Firefox component (Oracle).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and resides in the libvpx video codec library integrated into Firefox and Thunderbird. An attacker can trigger the overflow by crafting a malicious video file that, when processed by the libvpx decoder, writes beyond the bounds of an allocated heap buffer. Exploitation requires user interaction — specifically, a user must open or render the malicious video content in an affected browser or browser-like context. Mozilla notes that in Thunderbird, the flaw is not exploitable via email because scripting is disabled when reading mail, but it remains a risk in browser-like contexts (Mozilla Advisory, Mozilla Advisory).
Successful exploitation can lead to arbitrary code execution at the privilege level of the affected user, potentially resulting in full compromise of confidentiality, integrity, and availability of the affected system. An attacker who tricks a user into opening a malicious video file could execute arbitrary code, access sensitive data, install malware, or use the compromised system as a pivot point for lateral movement within a network. The broad deployment of Firefox and Thunderbird across enterprise and consumer environments significantly widens the potential attack surface (Mozilla Advisory, Mozilla Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.017%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. User interaction is required, which somewhat limits opportunistic exploitation, though drive-by attacks via malicious web pages or email attachments remain plausible vectors.
firefox, firefox-bin, or thunderbird (e.g., cmd.exe, /bin/sh, powershell.exe, curl, wget); unexpected process injection or memory anomalies in browser processes.Mozilla has released patched versions addressing this vulnerability: Firefox 147.0.4, Firefox ESR 140.7.1, Firefox ESR 115.32.1, Thunderbird 147.0.2, and Thunderbird 140.7.2 (Mozilla Advisory, Mozilla Advisory). Downstream Linux distributions including Red Hat, AlmaLinux, Rocky Linux, Oracle Linux, Debian, Ubuntu, SUSE, Slackware, and Mageia have also released updated packages. Oracle has addressed the issue in Oracle Solaris 11.4 via its April 2026 Third Party Bulletin (Oracle). IBM has issued guidance for affected Cloud Pak for Data System products. The primary remediation is to update all affected Firefox and Thunderbird installations to the patched versions immediately; as a temporary measure, organizations can restrict access to untrusted video content and enforce browser update policies through patch management systems.
Mozilla rated the vulnerability as "high" impact and issued emergency out-of-band security advisories (MFSA 2026-10 and MFSA 2026-11) on February 16, 2026, covering both Firefox and Thunderbird (Mozilla Advisory, Mozilla Advisory). Security news outlets including GBHackers, CyberSecurityNews, The Cyber Express, and IT Security News covered the release of the patched Firefox 147.0.4, highlighting the critical nature of the libvpx heap overflow fix. The vulnerability also received attention from CERT.at and various Linux distribution security teams, reflecting broad industry awareness and rapid patch adoption across the ecosystem.
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.8.0esr-1
sid
thunderbird: 1:140.8.0esr-1
trixie
thunderbird: 1:140.8.0esr-1
bionic (esm-infra)
libvpx
devel
libvpx: 1.16.0-2ubuntu1
focal (esm-infra)
libvpx
jammy
thunderbird
noble
libvpx: 1.14.0-1ubuntu2.3
questing
libvpx: 1.15.0-2.1ubuntu0.1
resolute
libvpx: 1.16.0-2ubuntu1
trusty (esm-infra-legacy)
libvpx
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."