HomeUpdatesMozilla Firefox: Fixes "Heap Buffer Overflow" vulnerability

Mozilla Firefox: Fixes “Heap Buffer Overflow” Vulnerability

Mozilla has released an emergency security update to address a critical vulnerability affecting the Firefox. The update, released as Firefox v147.0.4, resolves a serious issue Heap buffer overflow in the video codec library libvpx. The issue is tracked as CVE-2026-2447 and was discovered by security researcher jayjayjazz.

Mozilla Firefox

Alongside this release, Mozilla also pushed out updates to the Extended Support Release (ESR) channels: Firefox ESR 140.7.1 and Firefox ESR 115.32.1. The coordinated release reflects the severity of the vulnerability and its potential exposure on supported platforms.

See also: Notepad++ fixes update mechanism used to distribute malware

Firefox: Details of the Heap Buffer Overflow Vulnerability CVE-2026-2447

CVE-2026-2447 is classified as a Heap buffer overflow vulnerability in the libvpx library, which Firefox uses to process VP8 and VP9 video formats. These codecs are widely used for multimedia content on the web.

A Heap buffer overflow occurs when software writes data beyond the boundaries of allocated memory in the heap, the memory area reserved for dynamic operations during execution. When this happens, adjacent memory regions can be overwritten. In practice, this means that attackers can exploit such behavior by providing malicious or oversized input data, such as specially crafted video data.

If successful, the exploit could lead to arbitrary code execution, browser crashes , or even a complete system compromise.

See also: Zimbra patches XSS, XXE & LDAP Injection vulnerabilities

Mozilla Firefox: Fixes "Heap Buffer Overflow" Vulnerability

In the case of CVE-2026-2447, malicious actors could embed exploit payloads within seemingly legitimate media streams or web pages. A victim may only need to visit a compromised or malicious website or open tampered video content to trigger the Heap buffer overflow. Because Firefox v147 and earlier affected versions handle video decoding automatically, the exploit can occur without any obvious warning signs beyond normal browsing activity.

Mozilla has classified CVE-2026-2447 as “high” severity. The advisory notes that the vulnerability is serious, although no CVSS score has been released.

Affected and Fixed Versions

  • versions prior to 147.0.4 are vulnerable. The issue is fixed in 147.0.4.
  • versions prior to 140.7.1 are vulnerable. The issue is fixed in 140.7.1.
  • versions prior to 115.32.1 are vulnerable. The issue is fixed in 115.32.1.

Users running Firefox v147 prior to the 147.0.4 update are advised to update immediately. Enterprises maintaining ESR branches should prioritize this as ESR versions are often used in managed enterprise environments where delayed updates can increase exposure.

Mozilla Firefox: Fixes "Heap Buffer Overflow" Vulnerability

Exploitation Risk and the Broader Context

At the time of disclosure, there were no confirmed reports of widespread exploitation of the Firefox vulnerability. However, security experts note that Heap buffer overflow vulnerabilities are often chosen by cybercriminals due to their reliability and the potential for remote code execution. Because CVE-2026-2447 can be triggered remotely via malicious web content, it presents an attractive channel for drive-by attacks.

See also: Vulnerabilities in PDF platforms allow data theft

The libvpx library plays a central role in multimedia-heavy browsing sessions. As web platforms rely on embedded video and streaming formats such as VP8 and VP9, ​​vulnerabilities in codec handling can have wide-ranging consequences.

Mozilla recommends that users update via the browser's built-in mechanism, by going to Help > About Firefox, which automatically checks for and installs updates. Alternatively, new installers can be downloaded from Mozilla's official website.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS