CVE-2026-4712

7.5

Mozilla · Firefox, Thunderbird

An information disclosure vulnerability exists in the Widget: Cocoa component of Mozilla Firefox and Thunderbird, potentially allowing unauthorized access to sensitive data.

Executive summary

A critical information disclosure vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated attackers to potentially access sensitive information.

Vulnerability

This is an information disclosure vulnerability residing in the Widget: Cocoa component. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates this flaw is remotely exploitable by an unauthenticated attacker without requiring user interaction.

Business impact

The vulnerability poses a significant risk to organizational data privacy. Successful exploitation could lead to the unauthorized exposure of sensitive user or system information, potentially resulting in data breaches or further compromise of the internal environment. With a CVSS score of 7.5, this high severity flaw warrants immediate attention to prevent unauthorized data access.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 149 or 140.9, as applicable, to apply the necessary security fixes.

Proactive Monitoring: Review application and system access logs for anomalous patterns or unexpected requests originating from the Widget: Cocoa component.

Compensating Controls: Ensure that endpoint protection solutions are active and that organizational policies restrict the execution of untrusted or unauthorized browser extensions.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the ease of exploitation for this unauthenticated information disclosure vulnerability, organizations should prioritize patching their Mozilla browser and email client installations. Apply the vendor provided updates immediately to eliminate the exposure window and maintain the integrity of user data.

More Mozilla CVEs

Sources

Originally found and disclosed by Josh Aas, per the CVE Program record.