CVE-2026-6759

7.5

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability exists in the Widget: Cocoa component of Mozilla Firefox and Thunderbird, potentially allowing for denial of service.

Executive summary

A critical use-after-free vulnerability in the Widget: Cocoa component of Mozilla Firefox and Thunderbird exposes users to potential application crashes and denial of service.

Vulnerability

The vulnerability is a use-after-free flaw located within the Widget: Cocoa component. Based on the CVSS vector (AV:N/AC:L/PR:N/UI:N), this flaw is reachable by unauthenticated attackers without requiring user interaction.

Business impact

Successful exploitation of this vulnerability could lead to a denial of service, effectively crashing the affected browser or email client. With a CVSS score of 7.5, the risk is classified as High due to the ease of remote, unauthenticated exploitation. Such disruptions can hinder business productivity and potentially serve as a precursor to more complex memory corruption attacks.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 140.10 or 150 to resolve the underlying memory management defect.

Proactive Monitoring: Monitor system logs for recurring application crashes or unexpected terminations of the browser or mail client processes.

Compensating Controls: While standard perimeter defenses are limited against this browser-level flaw, utilizing endpoint protection software can help detect and block malicious payloads that attempt to trigger memory corruption.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk to organizational stability by allowing unauthenticated remote actors to cause service disruption. IT administrators should prioritize the deployment of the Mozilla security updates across all endpoints immediately to ensure full coverage and mitigate the risk of exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Steven Michaud, per the CVE Program record.