Junglewise Threat Intelligence

CVE-2026-6747: Mozilla Firefox and Thunderbird use-after-free in WebRTC

CVE-2026-6747 · Severity: high · CVSS 7.5 · Published 2026-04-21

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability has been identified in the WebRTC component of Mozilla Firefox and Thunderbird, which are widely used web browsing and email applications. This flaw could allow an attacker to potentially execute unauthorized code or cause the application to crash when a user interacts with malicious web content. While the risk is lower in Thunderbird because scripting is disabled by default for emails, users of both applications should update to the latest versions to protect their data and systems.

Technical details

A use-after-free vulnerability exists in the WebRTC component of Mozilla Firefox and Thunderbird. The flaw occurs when the application continues to use a memory pointer after it has been freed, which can be triggered by processing specifically crafted WebRTC content. An attacker could exploit this by enticing a user to visit a malicious website or interact with browser-like contexts within the affected applications. Successful exploitation could lead to memory corruption and potentially arbitrary code execution. The vulnerability is addressed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Affected products

  • Mozilla Firefox < 150
  • Mozilla Firefox ESR < 140.10
  • Mozilla Thunderbird < 150
  • Mozilla Thunderbird ESR < 140.10

Timeline

  • 2026-04-21: advisory: Mozilla Foundation Security Advisory published.
  • 2026-04-21: patched: Fixed versions released.

References

Related threats