Cyber Security News

Firefox v147.0.3 Released With Fix for Heap Buffer Overflow Vulnerability

Mozilla has released Firefox version 147.0.3, addressing a critical memory-related flaw that could allow attackers to execute arbitrary code by exploiting a heap buffer overflow issue in the browser’s media processing library.

The fix, part of the Mozilla Foundation Security Advisory 2026-10, improves overall browser security across both desktop and Extended Support Release (ESR) versions.

The vulnerability, tracked as CVE-2026-2447, was discovered in libvpx, a video codec library used by Firefox for handling VP8 and VP9 media streams.

Heap Buffer Overflow Fix Included

Reported by security researcher Jayjayjazz, the flaw could be triggered when a user visits a malicious website containing specially crafted video content.

If successfully exploited, the vulnerability could lead to memory corruption and potential remote code execution, giving attackers control over the user’s system.

The advisory considers the impact to be high, as this type of memory overflow vulnerability enables attackers to manipulate memory boundaries and inject malicious data into affected processes.

Mozilla’s engineers have resolved the issue by strengthening memory checks and enforcing secure handling of video frame buffers within libvpx.

The patch is included in Firefox 147.0.4, Firefox ESR 140.7.1, and Firefox ESR 115.32.1, released on February 16, 2026.

Users of earlier versions are strongly encouraged to update immediately to safeguard their browsers from potential exploitation.

The vulnerability fix highlights Mozilla’s ongoing commitment to user safety through rapid vulnerability response and transparent disclosure.

Mozilla also referenced Bug 2014390 in its security advisory, which provides additional technical details and a proof of concept demonstrating the issue’s reproducibility and the patch’s validation.

Routine browser updates remain critical for minimizing exposure to zero-day and memory-corruption vulnerabilities, particularly for applications that process complex data formats such as multimedia content.

Users and system administrators should ensure automatic updates are enabled to receive future security patches promptly.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago