CVE-2026-6747

7.5

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability exists in the WebRTC component of Mozilla Firefox and Thunderbird, potentially leading to a denial of service or code execution.

Executive summary

A critical use-after-free vulnerability in the WebRTC component of Mozilla Firefox and Thunderbird exposes users to potential system instability and remote exploitation.

Vulnerability

The vulnerability is a use-after-free defect within the WebRTC implementation. It allows an unauthenticated, remote attacker to trigger memory corruption, which typically results in application crashes or potentially arbitrary code execution.

Business impact

The exploitation of this vulnerability poses a significant risk to organizational endpoints, as WebRTC is a core component for real-time communication. With a CVSS score of 7.5, the impact is classified as high because it allows for unauthenticated remote access to disrupt or compromise browser-based processes. Successful exploitation could lead to service denial or the execution of unauthorized code within the context of the user session.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 150 or the ESR 140.10 release immediately.

Proactive Monitoring: Monitor browser logs for recurring crashes or abnormal memory usage patterns in the WebRTC process.

Compensating Controls: Deploy network-level traffic analysis to detect anomalous WebRTC signaling patterns and enforce endpoint security policies that restrict browser-based execution.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of memory corruption flaws in widely used software like Firefox and Thunderbird, organizations must prioritize the deployment of the provided security updates. Administrators should ensure that all browser instances are updated to the specified patched versions to eliminate the risk of exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Nan Wang, per the CVE Program record.