CVE-2026-6754

7.5

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability in the JavaScript Engine component allows for potential application crashes or unexpected behavior.

Executive summary

A critical use-after-free vulnerability in the Mozilla JavaScript Engine affects Firefox and Thunderbird, posing a significant risk of denial-of-service through application instability.

Vulnerability

This is a use-after-free vulnerability located within the JavaScript Engine component. The vulnerability can be triggered by an unauthenticated remote attacker via crafted web content, potentially leading to memory corruption or application termination.

Business impact

The CVSS score of 7.5 categorizes this as a High severity issue, primarily due to the potential for service disruption. Successful exploitation allows for the compromise of application availability, which could lead to significant operational downtime for users relying on these browsers or email clients for critical business communications.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to version 150, or the relevant ESR releases (115.35 or 140.10), as specified in the official Mozilla security advisories.

Proactive Monitoring: Monitor endpoint crash reports and system logs for recurring segmentation faults or abnormal termination patterns in the browser or email processes.

Compensating Controls: While no direct WAF control prevents use-after-free, enforcing strict browser security policies and disabling unnecessary JavaScript execution via group policy can reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the widespread deployment of the affected software, this vulnerability represents a significant risk to organizational stability. IT administrators should prioritize the deployment of the provided patches to all workstations and servers immediately to prevent potential service interruptions.

More Mozilla CVEs

Sources

Originally found and disclosed by Xuehao Guo, per the CVE Program record.