CVE-2026-4712
7.5Mozilla · Firefox, Thunderbird
An information disclosure vulnerability exists in the Widget: Cocoa component of Mozilla Firefox and Thunderbird, potentially allowing unauthorized access to sensitive data.
Executive summary
A critical information disclosure vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated attackers to potentially access sensitive information.
Vulnerability
This is an information disclosure vulnerability residing in the Widget: Cocoa component. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates this flaw is remotely exploitable by an unauthenticated attacker without requiring user interaction.
Business impact
The vulnerability poses a significant risk to organizational data privacy. Successful exploitation could lead to the unauthorized exposure of sensitive user or system information, potentially resulting in data breaches or further compromise of the internal environment. With a CVSS score of 7.5, this high severity flaw warrants immediate attention to prevent unauthorized data access.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 149 or 140.9, as applicable, to apply the necessary security fixes.
Proactive Monitoring: Review application and system access logs for anomalous patterns or unexpected requests originating from the Widget: Cocoa component.
Compensating Controls: Ensure that endpoint protection solutions are active and that organizational policies restrict the execution of untrusted or unauthorized browser extensions.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given the ease of exploitation for this unauthenticated information disclosure vulnerability, organizations should prioritize patching their Mozilla browser and email client installations. Apply the vendor provided updates immediately to eliminate the exposure window and maintain the integrity of user data.
More Mozilla CVEs
Sources
Originally found and disclosed by Josh Aas, per the CVE Program record.