CVE-2026-6772
7.5Mozilla · Firefox, Thunderbird
Incorrect boundary conditions in the NSS libraries allow for potential unauthorized data access.
Executive summary
A critical vulnerability in the Mozilla NSS library within Firefox and Thunderbird may allow unauthorized access to information due to improper boundary condition handling.
Vulnerability
The flaw exists in the NSS (Network Security Services) component, where incorrect boundary condition checks can be exploited by an unauthenticated remote attacker to gain unauthorized access to sensitive information.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation could lead to the unauthorized disclosure of sensitive user data, potentially resulting in privacy breaches, loss of intellectual property, or regulatory compliance failures depending on the nature of the data processed by the browser or mail client.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to the versions specified in the Mozilla security advisories (150, 115.35 ESR, or 140.10 ESR) to ensure the patched NSS libraries are utilized.
Proactive Monitoring: Review enterprise endpoint logs for unusual memory access patterns or unexpected crashes associated with the NSS library during network communication.
Compensating Controls: Ensure that network traffic is inspected by robust security appliances, though note that this vulnerability primarily concerns internal library processing rather than network-level payloads.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the ubiquity of Firefox and Thunderbird in enterprise environments, this vulnerability poses a significant risk to data confidentiality. Administrators must prioritize the deployment of the provided security updates across all workstations to remediate the flaw in the underlying NSS component. Immediate patching is the only effective way to mitigate this risk.
More Mozilla CVEs
Sources
Originally found and disclosed by sseehra, per the CVE Program record.