Junglewise Threat Intelligence

CVE-2026-6748: Mozilla Firefox and Thunderbird uninitialized memory in Web Codecs

CVE-2026-6748 · Severity: critical · CVSS 9.8 · Published 2026-04-21

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Red Hat Enterprise Linux, Mozilla Firefox. Vendors: Mozilla, Red Hat.

Executive brief

A vulnerability exists in the web browsers and email clients Firefox and Thunderbird within the component responsible for processing audio and video content. This flaw could allow an attacker to potentially access sensitive information or execute unauthorized commands if a user visits a malicious website or interacts with malicious media content. While Thunderbird users are generally protected while reading standard emails, the risk remains in browser-like contexts within the application.

Technical details

A vulnerability classified as 'Use of Uninitialized Variable' (CWE-457) or 'Access of Uninitialized Pointer' (CWE-824) exists in the Audio/Video: Web Codecs component of Mozilla browsers and email clients. The flaw occurs when the application attempts to use memory that has not been properly initialized, which can lead to memory corruption. An attacker can exploit this over the network by enticing a user to process specially crafted media content. Successful exploitation could result in information disclosure, a crash, or potentially arbitrary code execution. The issue is fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Affected products

  • Mozilla Firefox < 150
  • Mozilla Firefox ESR < 140.10
  • Mozilla Thunderbird < 150, < 140.10
  • Red Hat Enterprise Linux 7, 10.0

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: patched
  • 2026-04-21: advisory

References

Related threats