CVE-2026-6750
8.8Mozilla · Firefox, Thunderbird
A privilege escalation vulnerability exists in the Graphics: WebRender component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to achieve full system impact.
Executive summary
A critical privilege escalation vulnerability in the Graphics: WebRender component of Mozilla Firefox and Thunderbird exposes users to potential system compromise.
Vulnerability
This is a privilege escalation flaw located within the WebRender graphics component. The vulnerability is exploitable by an unauthenticated, remote attacker who lures a user into interacting with malicious content, as indicated by the CVSS vector requiring user interaction.
Business impact
The vulnerability carries a high CVSS score of 8.8, reflecting the potential for total impact on confidentiality, integrity, and availability. Successful exploitation could allow a remote attacker to execute arbitrary code or escalate privileges within the context of the application, leading to unauthorized access to sensitive user data or complete compromise of the workstation.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to the identified patched versions (150, or the respective ESR releases 115.35/140.10) immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or unexpected modifications to system files originating from the browser or email client processes.
Compensating Controls: Ensure that browser security settings, such as sandboxing, remain enabled and verify that endpoint protection solutions are configured to detect known malicious patterns associated with browser-based exploits.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this privilege escalation, all IT administrators should prioritize the deployment of the latest security updates for Mozilla Firefox and Thunderbird. Failure to patch these browsers leaves workstations vulnerable to high-impact attacks, and immediate action is required to maintain a secure computing environment.
More Mozilla CVEs
Sources
Originally found and disclosed by choeseyeong, per the CVE Program record.