CVE-2026-6766
7.5Mozilla · Firefox, Thunderbird
A boundary condition error in the NSS Libraries component affects Mozilla Firefox and Thunderbird, potentially leading to unauthorized data disclosure.
Executive summary
A critical boundary condition vulnerability in the NSS component of Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to potentially access sensitive information.
Vulnerability
This vulnerability involves incorrect boundary conditions within the NSS (Network Security Services) library. The flaw is exploitable by an unauthenticated remote attacker via network vectors without requiring user interaction.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation could lead to the unauthorized disclosure of sensitive data processed by the browser or mail client, potentially compromising user credentials, private communications, or internal corporate information. This flaw poses a significant risk to organizational confidentiality and privacy standards.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 150 or the ESR version 140.10 immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor network traffic for unusual patterns associated with NSS-related protocols and review application logs for signs of unexpected memory access or crashes.
Compensating Controls: Ensure that endpoint protection software is active and consider restricting network access for unpatched legacy systems until updates can be deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the widespread use of the NSS library, this vulnerability represents a significant risk to end-user workstations. Organizations should prioritize the deployment of the Mozilla security updates mentioned above to ensure that the boundary condition error is remediated and the risk of unauthorized data access is eliminated.
More Mozilla CVEs
Sources
Originally found and disclosed by Haruto Kimura, per the CVE Program record.