Junglewise Threat Intelligence

CVE-2026-6749: Mozilla Firefox and Thunderbird information disclosure in Canvas2D

CVE-2026-6749 · Severity: high · CVSS 7.5 · Published 2026-04-21

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla, Red Hat.

Executive brief

A vulnerability in the Canvas2D graphics component of Mozilla Firefox and Thunderbird could allow an attacker to access sensitive information. This occurs because the software fails to properly clear memory before using it, potentially exposing data from previously visited websites or other browser processes. Users are advised to update to the latest versions of Firefox, Firefox ESR, or Thunderbird to mitigate this risk.

Technical details

An information disclosure vulnerability exists in the Graphics: Canvas2D component of Mozilla browsers and mail clients. The flaw is caused by the use of uninitialized memory (CWE-908/CWE-824), which can be leveraged by a remote attacker to read sensitive data that remains in memory from previous operations. The vulnerability is reachable via the network without authentication. Mozilla has addressed this issue in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. Red Hat has also issued multiple errata for affected Enterprise Linux packages.

Affected products

  • Mozilla Firefox < 150
  • Mozilla Firefox ESR < 115.35, < 140.10
  • Mozilla Thunderbird < 150, < 140.10
  • Red Hat Enterprise Linux Server (v. 7 ELS)

Timeline

  • 2026-04-21: advisory: Mozilla Foundation Security Advisory published
  • 2026-04-21: patched: Fixed in Firefox 150 and related versions

References

Related threats