
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4715 is an uninitialized memory vulnerability in the Graphics: Canvas2D component of Mozilla Firefox and Thunderbird. Reported by Jun Yang and disclosed on March 24, 2026, it affects Firefox versions prior to 149 and Firefox ESR versions prior to 140.9, as well as the corresponding Thunderbird releases. The vulnerability was assigned a CVSS v3.1 base score of 9.1 (Critical) by Feedly's estimate, though Mozilla's own advisory rates its impact as "moderate" (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).
The vulnerability is classified under CWE-908 (Use of Uninitialized Resource) and CWE-824 (Access of Uninitialized Pointer), stemming from the Canvas2D rendering subsystem failing to properly initialize memory before use. When a browser processes certain Canvas2D rendering operations, uninitialized memory regions may be accessed or exposed, potentially leaking heap contents to an attacker-controlled context. The flaw is remotely exploitable over the network without authentication or user interaction, as Canvas2D operations can be triggered via JavaScript on any web page (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9). The underlying bug is tracked as Mozilla Bug 2018405, though the bug report is access-restricted.
Successful exploitation of CVE-2026-4715 could allow a remote, unauthenticated attacker to read uninitialized heap memory from the Firefox or Thunderbird process, leading to sensitive information disclosure — such as credentials, session tokens, or other in-memory data. The vulnerability also carries a high availability impact per the CVSS scoring, suggesting potential for application instability or crashes. While integrity is not directly affected, leaked memory contents could facilitate further attacks, including bypassing ASLR or enabling exploitation of other vulnerabilities (Mozilla Advisory Firefox 149, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.000170, indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is detectable by multiple commercial scanners including Qualys and Nessus.
Mozilla has released patches addressing CVE-2026-4715 in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9. Users and administrators should update to these versions or later immediately. As a temporary workaround where patching is not immediately feasible, restricting user access to untrusted web content or disabling Canvas2D functionality (if operationally feasible) may reduce exposure. Linux distribution vendors including Red Hat, AlmaLinux, Rocky Linux, Debian, openSUSE, and Amazon Linux have also issued updated packages (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).
Mozilla rated the vulnerability's impact as "moderate" in its official advisories, a lower severity than the CVSS 9.1 score assigned by automated scoring systems, reflecting the limited exploitation potential at time of disclosure (Mozilla Advisory Firefox 149). Security news outlets including The Hacker Wire and CyberSecurityNews covered the Firefox 149 release, noting the breadth of vulnerabilities addressed in the update (The Hacker Wire). Downstream Linux distributions responded promptly with security advisories and updated packages across major platforms.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."