CVE-2026-6781

7.5

Mozilla · Firefox, Thunderbird

A denial-of-service vulnerability exists in the Audio/Video Playback component of Mozilla Firefox and Thunderbird, allowing unauthenticated remote attackers to crash the application.

Executive summary

Mozilla Firefox and Thunderbird are vulnerable to a remote denial-of-service attack, which could lead to service disruption and application instability.

Vulnerability

This is a denial-of-service vulnerability located within the Audio/Video Playback component. The vulnerability is automatable and can be triggered by an unauthenticated remote attacker with no required user interaction.

Business impact

Successful exploitation of this vulnerability results in the unexpected termination of the browser or email client. Given the CVSS score of 7.5, this high-severity flaw poses a risk to operational continuity, as frequent application crashes can disrupt user workflows and reduce productivity.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 150 or later to apply the necessary security patches.

Proactive Monitoring: Review application crash logs for patterns associated with media playback failures or anomalous memory usage.

Compensating Controls: Ensure that automated software update policies are enforced across the enterprise to ensure rapid deployment of security fixes.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The vulnerability presents a significant risk to organizational stability by allowing unauthenticated actors to disrupt core productivity tools. It is recommended that IT administrators prioritize the deployment of Firefox and Thunderbird version 150 across all endpoints to mitigate this risk immediately.

More Mozilla CVEs

Sources

Originally found and disclosed by LatticeBased, per the CVE Program record.