Mozilla released an out-of-band update to Firefox 147.0.4 to fix CVE-2026-2447, a high-impact heap buffer overflow in the libvpx video codec library used to decode VP8/VP9 content. The flaw could be triggered via specially crafted video/media streams delivered through web pages, potentially leading to arbitrary code execution, browser crashes, or broader system compromise; the issue was reported by researcher jayjayjazz. Mozilla also shipped corresponding fixes to supported ESR lines (Firefox ESR 140.7.1 and Firefox ESR 115.32.1), reflecting the breadth of exposure across supported platforms.
Canada’s Canadian Centre for Cyber Security echoed Mozilla’s guidance, urging organizations to apply the updates across Firefox, Firefox ESR, and Thunderbird (per Mozilla’s advisories) to remediate the affected versions. Separate reporting described a different Firefox RCE condition tied to a SpiderMonkey WebAssembly GC logic error (a & vs | typo) and separate Microsoft Edge items (including an advisory noting an exploitable CVE-2026-2441 and an article focused on Edge 145 enterprise security features); those are not part of the libvpx CVE-2026-2447 disclosure and should be tracked independently.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-17, the Canadian Centre for Cyber Security published advisory AV26-136 highlighting Mozilla's security fixes and urging users and administrators to review the advisories and apply the necessary updates. The notice referenced affected Firefox, Firefox ESR, and Thunderbird versions.
Mozilla issued an out-of-band update to address CVE-2026-2447, a high-severity heap buffer overflow in the libvpx video codec library used for VP8/VP9 decoding in Firefox. The flaw, reported by researcher jayjayjazz, could be triggered by crafted video content and may allow crashes, arbitrary code execution, or system compromise.
On 2026-02-16, Mozilla published security advisories covering vulnerabilities in multiple products, including Firefox, Firefox ESR, and Thunderbird. The advisories included fixes in Firefox 147.0.4, Firefox ESR 140.7.1 and 115.32.1, and Thunderbird 147.0.2 and 140.7.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.