CVE-2026-6759
7.5Mozilla · Firefox, Thunderbird
A use-after-free vulnerability exists in the Widget: Cocoa component of Mozilla Firefox and Thunderbird, potentially allowing for denial of service.
Executive summary
A critical use-after-free vulnerability in the Widget: Cocoa component of Mozilla Firefox and Thunderbird exposes users to potential application crashes and denial of service.
Vulnerability
The vulnerability is a use-after-free flaw located within the Widget: Cocoa component. Based on the CVSS vector (AV:N/AC:L/PR:N/UI:N), this flaw is reachable by unauthenticated attackers without requiring user interaction.
Business impact
Successful exploitation of this vulnerability could lead to a denial of service, effectively crashing the affected browser or email client. With a CVSS score of 7.5, the risk is classified as High due to the ease of remote, unauthenticated exploitation. Such disruptions can hinder business productivity and potentially serve as a precursor to more complex memory corruption attacks.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 140.10 or 150 to resolve the underlying memory management defect.
Proactive Monitoring: Monitor system logs for recurring application crashes or unexpected terminations of the browser or mail client processes.
Compensating Controls: While standard perimeter defenses are limited against this browser-level flaw, utilizing endpoint protection software can help detect and block malicious payloads that attempt to trigger memory corruption.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant risk to organizational stability by allowing unauthenticated remote actors to cause service disruption. IT administrators should prioritize the deployment of the Mozilla security updates across all endpoints immediately to ensure full coverage and mitigate the risk of exploitation.
More Mozilla CVEs
Sources
Originally found and disclosed by Steven Michaud, per the CVE Program record.