Junglewise Threat Intelligence

CVE-2026-6746: Mozilla Firefox and Thunderbird use-after-free in DOM component

CVE-2026-6746 · Severity: high · CVSS 7.5 · Published 2026-04-21

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla, Red Hat.

Executive brief

A vulnerability has been identified in Mozilla Firefox and Thunderbird that affects how the software handles web page elements. This flaw could allow a malicious website to cause the application to crash or behave unexpectedly by accessing memory that has already been released. Users should update to the latest versions of their browser or email client to prevent potential service disruptions.

Technical details

A use-after-free vulnerability exists in the DOM: Core & HTML component of Mozilla Firefox and Thunderbird. The flaw occurs when the application attempts to access a memory location after it has been freed, typically during the processing of HTML or DOM elements. An attacker could exploit this by enticing a user to visit a specially crafted webpage, potentially leading to a denial-of-service (application crash) or, in some scenarios, arbitrary code execution. The vulnerability is fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Affected products

  • Mozilla Firefox < 150
  • Mozilla Firefox ESR < 115.35, < 140.10
  • Mozilla Thunderbird < 150, < 140.10
  • Red Hat Enterprise Linux Server (v. 7 ELS) affected

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: advisory
  • 2026-04-21: patched

References

Related threats