CVE-2026-4711
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-4711 is a use-after-free vulnerability in the Widget: Cocoa component of Mozilla Firefox and Thunderbird, affecting macOS systems where the Cocoa UI framework is used. It was discovered by Josh Aas and disclosed on March 24, 2026, as part of Mozilla's coordinated security advisory release. Affected versions include Firefox prior to 149.0 and Firefox ESR prior to 140.9.0, as well as the corresponding Thunderbird releases. Mozilla rates the vulnerability's impact as "moderate," while the NVD assigns a CVSS v3.1 base score of 9.8 (Critical) (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Firefox's macOS-specific Widget: Cocoa component — the layer responsible for native macOS UI widget rendering. A use-after-free condition occurs when a memory object associated with a Cocoa widget is freed but a dangling reference to it is subsequently dereferenced, potentially allowing an attacker to control the freed memory region and redirect execution flow. The bug was tracked internally as Mozilla Bug 2017002 (access-restricted) and reported by Josh Aas (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9). No public proof-of-concept or detailed technical write-up has been released as of the time of this report.

Impact

Successful exploitation of this vulnerability could allow an attacker to achieve arbitrary code execution within the context of the Firefox or Thunderbird process on macOS systems, with potential for high impact to confidentiality, integrity, and availability. An attacker who controls freed memory could redirect program execution to attacker-controlled code, potentially enabling data theft, installation of malware, or further lateral movement within the affected system. The scope is limited to macOS platforms due to the Cocoa-specific nature of the affected component (Mozilla Advisory ESR 140.9, Feedly).

Exploitability

As of the time of this report, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability has an EPSS score of approximately 0.017% (0.000170), indicating a low current probability of exploitation in the wild. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported in connection with this CVE.

Mitigation and workarounds

Mozilla has released patches addressing CVE-2026-4711 in Firefox 149.0, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9. Users and administrators should immediately upgrade to these versions or later. No configuration-based workaround is available; upgrading is the only effective remediation. Organizations managing macOS endpoints should prioritize patching Firefox and Thunderbird installations, particularly in environments where users browse untrusted content (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).

Community reactions

The vulnerability was covered by security news outlets including The Hacker Wire, which highlighted it as part of a broader batch of Firefox ESR fixes released on March 24, 2026 (The Hacker Wire). Linux distribution vendors including Red Hat, AlmaLinux, Rocky Linux, openSUSE, and Amazon Linux have issued downstream advisories and updated packages. General community reaction has been routine, consistent with a patched moderate-severity browser vulnerability with no known active exploitation.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management