CVE-2026-6782
7.5Mozilla · Firefox, Thunderbird
A vulnerability in the IP Protection component of Mozilla Firefox and Thunderbird allows for unauthorized information disclosure.
Executive summary
An information disclosure vulnerability in Mozilla Firefox and Thunderbird poses a significant risk to user privacy and data confidentiality.
Vulnerability
The flaw resides within the IP Protection component, allowing an unauthenticated remote attacker to potentially access sensitive information due to improper handling of network traffic.
Business impact
The successful exploitation of this vulnerability could lead to the unauthorized exposure of sensitive user network information, compromising individual privacy and potentially facilitating targeted attacks. With a CVSS score of 7.5, this issue is classified as High severity, indicating that the potential for data leakage is significant and requires immediate attention to protect organizational and user data.
Remediation
Immediate Action: Update all instances of Mozilla Firefox and Mozilla Thunderbird to version 150 or later to ensure the vulnerability is patched.
Proactive Monitoring: Review web server and network traffic logs for unusual patterns originating from the IP Protection component or associated network requests.
Compensating Controls: While no direct virtual patch exists, restricting unnecessary network traffic or using organizational proxy configurations can limit the exposure of internal IP information until updates are deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity of this information disclosure vulnerability, organizations should prioritize the deployment of Firefox and Thunderbird version 150 across all enterprise endpoints. Timely patching is essential to prevent potential privacy breaches and to ensure the integrity of network communications within the managed environment.
More Mozilla CVEs
Sources
Originally found and disclosed by Yuki Umemura, per the CVE Program record.