CVE-2026-6746

7.5

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability exists in the DOM Core and HTML components of Mozilla Firefox and Thunderbird, potentially leading to a crash or undefined behavior.

Executive summary

A critical use-after-free vulnerability in the DOM component of Mozilla Firefox and Thunderbird creates a high risk of application instability or potential exploitation.

Vulnerability

This is a use-after-free flaw located within the DOM Core and HTML engine, which can be triggered by an unauthenticated attacker to cause memory corruption or denial of service.

Business impact

The CVSS score of 7.5 indicates a high severity rating, primarily due to the potential for application crashes and the high likelihood of successful exploitation if left unpatched. Successful exploitation could lead to significant operational disruption for end users and potential security compromises if the memory corruption is leveraged for further malicious activity.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 150, or the latest ESR versions (115.35 or 140.10) as applicable, to resolve the underlying memory management defect.

Proactive Monitoring: Monitor system logs for repeated application crashes that may indicate an attempt to trigger the use-after-free condition.

Compensating Controls: Ensure that endpoint protection software is active to detect and block suspicious browser-based activities, and restrict the execution of untrusted scripts where possible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the nature of use-after-free vulnerabilities in core components, this issue presents a notable risk to browser and mail client integrity. IT administrators should prioritize the deployment of the Mozilla security updates across all managed endpoints to ensure protection against potential exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using C, per the CVE Program record.