
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4705 is an undefined behavior vulnerability in the WebRTC: Signaling component of Mozilla Firefox and Thunderbird. It affects Firefox versions prior to 149 and Firefox ESR versions prior to 140.9, as well as the corresponding Thunderbird releases (149 and 140.9). The vulnerability was disclosed on March 24, 2026, alongside a broad set of security fixes in Mozilla Foundation Security Advisories 2026-20 and 2026-22. Feedly's threat intelligence assigns it a CVSS v3.1 base score of 9.8 (Critical), though Mozilla's own advisory rates its impact as "moderate" (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).
The vulnerability is classified under CWE-475 (Undefined Behavior for Input to API) and CWE-758 (Reliance on Undefined, Unspecified, or Implementation-Defined Behavior), indicating that the WebRTC signaling subsystem invokes operations whose behavior is not guaranteed by the language or platform specification. This can manifest as memory corruption, unexpected control flow, or other unpredictable states depending on the compiler and runtime environment. The flaw was discovered by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic, and is tracked internally as Mozilla bug 2014873 (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9). No public technical write-up or proof-of-concept code has been identified at this time.
Successful exploitation of this undefined behavior vulnerability in the WebRTC Signaling component could result in confidentiality, integrity, and availability impacts, potentially enabling an attacker to read sensitive browser memory, corrupt data, or crash the affected application. Because WebRTC is a network-accessible, browser-integrated component, exploitation could be triggered remotely without requiring user interaction or elevated privileges, making the attack surface broad. The scope is limited to the affected browser or email client process, but memory corruption primitives could potentially be chained with other vulnerabilities for sandbox escape or code execution (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).
As of the time of this report, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.015% (0.000150), indicating a very low current probability of exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The vulnerability was discovered through AI-assisted security research using Anthropic's Claude, which is a notable aspect of its discovery context (VulnCheck Blog).
Mozilla has released patches addressing this vulnerability in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9. Users and administrators should update all affected installations to these versions or later immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation. Enterprise deployments should prioritize patching given the network-accessible nature of the WebRTC component (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9). Linux distribution vendors including Red Hat, Debian, openSUSE, AlmaLinux, Rocky Linux, and Amazon Linux have also issued updated packages (Red Hat Errata).
The vulnerability attracted attention partly because it was discovered using AI-assisted research — specifically, Anthropic's Claude model was credited alongside the human researchers, which VulnCheck highlighted in a blog post about "Anthropic Glasswing CVEs" (VulnCheck Blog). Security news outlets including CyberSecurityNews and HealSecurity covered the broader Firefox 149 release, noting the large number of vulnerabilities (37+) addressed in the update (CyberSecurityNews). Community discussion on Mastodon and Infosec.exchange noted the release, though no significant controversy or debate specific to CVE-2026-4705 was observed.
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.9.0esr-1~deb12u1
sid
thunderbird: 1:140.9.0esr-1
trixie
thunderbird: 1:140.9.0esr-1~deb13u1
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird
noble
firefox
questing
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."