Junglewise Threat Intelligence

CVE-2026-6750: Mozilla Firefox and Thunderbird privilege escalation in WebRender

CVE-2026-6750 · Severity: high · CVSS 8.8 · Published 2026-04-21

Technologies: Mozilla Thunderbird, Red Hat Enterprise Linux Server, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla, Red Hat.

Executive brief

A security vulnerability has been identified in the WebRender component of Mozilla Firefox and Thunderbird, which are widely used web browsing and email applications. This flaw could allow an attacker to gain elevated privileges on a user's system if they are tricked into visiting a malicious website or viewing a specially crafted email. Such an exploit could lead to unauthorized access to sensitive data or the ability to perform actions as a higher-privileged user. Mozilla has released updates to address this issue across its supported software versions.

Technical details

A privilege escalation vulnerability exists in the Graphics: WebRender component of Mozilla Firefox and Thunderbird. The flaw is categorized as an incorrect privilege assignment (CWE-266) or improper privilege management (CWE-269). While specific root cause details are restricted in the associated Bugzilla report (Bug 2023407), the vulnerability is reachable via the network and requires user interaction, such as visiting a malicious webpage. Successful exploitation allows an attacker to escalate their privileges within the context of the application or the underlying operating system. The issue is resolved in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Affected products

  • Mozilla Firefox < 150
  • Mozilla Firefox ESR < 115.35, < 140.10
  • Mozilla Thunderbird < 150, < 140.10
  • Red Hat Enterprise Linux Server 7 ELS

Timeline

  • 2026-04-21: advisory: Mozilla Foundation Security Advisory published
  • 2026-04-21: disclosed: CVE-2026-6750 published to NVD

References

Related threats