CVE-2026-6780

7.5

Mozilla · Firefox, Thunderbird

A denial of service vulnerability exists in the Audio/Video Playback component of Mozilla Firefox and Thunderbird, allowing unauthenticated remote attackers to disrupt service.

Executive summary

A critical denial of service vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to crash the application, potentially leading to significant service disruption.

Vulnerability

This vulnerability resides in the Audio/Video Playback component, where an unauthenticated remote attacker can trigger a denial of service condition through specially crafted media content. The flaw is automatable and requires no user interaction or authentication to execute.

Business impact

The ability for an unauthenticated attacker to cause a denial of service directly impacts the availability of business critical communication and web browsing tools. Given the CVSS score of 7.5, this high severity flaw poses a risk of widespread operational disruption if left unpatched. Organizations relying on these products for daily workflows may experience significant downtime and productivity loss.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Mozilla Thunderbird to version 150 or later immediately to apply the vendor-supplied security fixes.

Proactive Monitoring: Monitor system logs for unusual crashes or instability in browser and mail client processes that may indicate attempted exploitation of the media playback engine.

Compensating Controls: While no direct virtual patch exists, ensure that endpoint security software is configured to scan incoming media files and restrict the execution of unauthorized or untrusted content.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates immediate action, as it allows for remote service disruption without requiring user interaction. Administrators should prioritize the deployment of version 150 across all enterprise endpoints to eliminate the risk posed by this denial of service flaw.

More Mozilla CVEs

Sources

Originally found and disclosed by LatticeBased, per the CVE Program record.