#VU124306 Out-of-bounds write in Mozilla products - CVE-2026-4721
Published: March 24, 2026
Mozilla Firefox
Firefox ESR
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory safety bugs in multiple components when processing content. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.
Multiple memory safety bugs were fixed; some showed evidence of memory corruption, indicating potential for arbitrary code execution.
Remediation
External links
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-21/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-22/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2013762
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2015291
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2016591
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2016661
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2016664
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2017303
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2017894
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2018090
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2018196
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2018379
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2019112
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022090
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022243
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022351
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022478
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022676