CVE-2026-4705
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-4705 is an undefined behavior vulnerability in the WebRTC: Signaling component of Mozilla Firefox and Thunderbird. It affects Firefox versions prior to 149 and Firefox ESR versions prior to 140.9, as well as the corresponding Thunderbird releases (149 and 140.9). The vulnerability was disclosed on March 24, 2026, alongside a broad set of security fixes in Mozilla Foundation Security Advisories 2026-20 and 2026-22. Feedly's threat intelligence assigns it a CVSS v3.1 base score of 9.8 (Critical), though Mozilla's own advisory rates its impact as "moderate" (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).

Technical details

The vulnerability is classified under CWE-475 (Undefined Behavior for Input to API) and CWE-758 (Reliance on Undefined, Unspecified, or Implementation-Defined Behavior), indicating that the WebRTC signaling subsystem invokes operations whose behavior is not guaranteed by the language or platform specification. This can manifest as memory corruption, unexpected control flow, or other unpredictable states depending on the compiler and runtime environment. The flaw was discovered by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic, and is tracked internally as Mozilla bug 2014873 (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9). No public technical write-up or proof-of-concept code has been identified at this time.

Impact

Successful exploitation of this undefined behavior vulnerability in the WebRTC Signaling component could result in confidentiality, integrity, and availability impacts, potentially enabling an attacker to read sensitive browser memory, corrupt data, or crash the affected application. Because WebRTC is a network-accessible, browser-integrated component, exploitation could be triggered remotely without requiring user interaction or elevated privileges, making the attack surface broad. The scope is limited to the affected browser or email client process, but memory corruption primitives could potentially be chained with other vulnerabilities for sandbox escape or code execution (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).

Exploitability

As of the time of this report, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.015% (0.000150), indicating a very low current probability of exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The vulnerability was discovered through AI-assisted security research using Anthropic's Claude, which is a notable aspect of its discovery context (VulnCheck Blog).

Mitigation and workarounds

Mozilla has released patches addressing this vulnerability in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9. Users and administrators should update all affected installations to these versions or later immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation. Enterprise deployments should prioritize patching given the network-accessible nature of the WebRTC component (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9). Linux distribution vendors including Red Hat, Debian, openSUSE, AlmaLinux, Rocky Linux, and Amazon Linux have also issued updated packages (Red Hat Errata).

Community reactions

The vulnerability attracted attention partly because it was discovered using AI-assisted research — specifically, Anthropic's Claude model was credited alongside the human researchers, which VulnCheck highlighted in a blog post about "Anthropic Glasswing CVEs" (VulnCheck Blog). Security news outlets including CyberSecurityNews and HealSecurity covered the broader Firefox 149 release, noting the large number of vulnerabilities (37+) addressed in the update (CyberSecurityNews). Community discussion on Mastodon and Infosec.exchange noted the release, though no significant controversy or debate specific to CVE-2026-4705 was observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

thunderbird: 1:140.9.0esr-1~deb12u1

Fixed

sid

thunderbird: 1:140.9.0esr-1

Fixed

trixie

thunderbird: 1:140.9.0esr-1~deb13u1

Fixed

Ubuntu

Affected

bionic (esm-apps)

mozjs38

Unknown

devel

firefox

Not Affected

jammy

thunderbird

Affected

noble

firefox

Not Affected

questing

firefox

Not Affected

resolute

firefox

Not Affected

RHEL / CentOS

Fixed

RHEL 8

:appstream:firefox-0:140.9.0-1.el8_10.src

Fixed

RHEL 9

:appstream:firefox-0:140.9.0-1.el9_0.src

Fixed

RHEL 10

firefox-0:140.9.0-1.el10_0.src

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management