cve 2026 2447

About this tag
CVE-2026-2447 is a heap-buffer-overflow vulnerability in the libvpx video codec that was patched in Firefox 147.0.4. Mozilla backported the fix to multiple ESR branches. The vulnerability could cause crashes or potentially allow code execution. This tag covers discussions about the CVE, its impact on Firefox, and the patch released to address it.
  1. Firefox 147.0.4 Fixes Blank New Tab and Libvpx CVE-2026-2447 Patch

    Mozilla pushed a small but important maintenance release for the stable channel this week: Firefox 147.0.4 ships a targeted user-experience fix that stops some users from seeing a blank New Tab (about:home/about:newtab) and closes a heap-buffer-overflow in the libvpx video codec (tracked as...