CVE-2026-5735
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-5735 is a memory safety vulnerability affecting Mozilla Firefox and Thunderbird, involving memory corruption bugs (including out-of-bounds reads and writes) that could potentially be exploited to achieve arbitrary code execution. It affects Firefox versions prior to 149.0.2 and Thunderbird versions prior to 149.0.2, with the bugs specifically present in Firefox 149.0.1 and Thunderbird 149.0.1. The vulnerability was disclosed on April 7, 2026, and was reported by Brian Grinstead, Christian Holler, and the Mozilla Fuzzing Team. It carries a CVSS v3.1 base score of 9.8 (Critical) (Mozilla Advisory, GitHub Advisory).

Technical details

The vulnerability is rooted in memory safety bugs classified under CWE-787 (Out-of-bounds Write) and CWE-125 (Out-of-bounds Read), present in the Firefox and Thunderbird browser engines. These bugs showed evidence of memory corruption, and Mozilla assessed that with sufficient effort they could be exploited to run arbitrary code. The attack vector is network-based, requires no privileges and no user interaction, and the specific bugs are tracked in Mozilla's Bugzilla under bug IDs 2025475 and 2025477. For Thunderbird specifically, Mozilla notes that these flaws generally cannot be exploited through email because scripting is disabled when reading mail, but they represent risks in browser or browser-like contexts (Mozilla Advisory, Mozilla Advisory, GitHub Advisory).

Impact

Successful exploitation of CVE-2026-5735 could allow a remote, unauthenticated attacker to execute arbitrary code on the affected system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker could leverage this to install malware, exfiltrate sensitive data, or use the compromised browser process as a foothold for lateral movement within a network. All users running Firefox or Thunderbird versions below 149.0.2 are at risk (Mozilla Advisory, GitHub Advisory).

Mitigation and workarounds

Mozilla has released patched versions addressing this vulnerability: users should update Firefox to version 149.0.2 or later and Thunderbird to version 149.0.2 or later immediately. No configuration-based workarounds are available; upgrading is the only remediation. Organizations should enable automatic updates where possible to ensure timely deployment of security patches (Mozilla Advisory, Mozilla Advisory).

Community reactions

The CIS Security advisory noted that multiple vulnerabilities in Mozilla products, including CVE-2026-5735, could allow for arbitrary code execution, recommending prompt patching. OpenSUSE and other Linux distributions issued security announcements to push updated Firefox packages to their users. Community discussion on platforms such as Mastodon (infosec.exchange) and security-focused forums acknowledged the high CVSS score but noted the absence of active exploitation. Overall, the security community treated this as a routine but high-priority browser update (CIS Advisory, OpenSUSE).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16412CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesJul 21, 2026
CVE-2026-16411CRITICAL9.8
  • NixOS logoNixOS
  • firefox
NoYesJul 21, 2026
CVE-2026-16410CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesJul 21, 2026
CVE-2026-16408CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesJul 21, 2026
CVE-2026-16409HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management