Junglewise Threat Intelligence

CVE-2026-6753: Mozilla Firefox and Thunderbird out-of-bounds write in WebRTC

CVE-2026-6753 · Severity: high · CVSS 7.3 · Published 2026-04-21

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Red Hat, Mozilla.

Executive brief

A vulnerability exists in the WebRTC component of Mozilla Firefox and Thunderbird, which are widely used web browsers and email clients. This flaw involves incorrect boundary conditions that could allow an attacker to cause memory corruption or potentially execute unauthorized actions. While Thunderbird users are generally protected when reading standard emails because scripting is disabled, the risk remains in browser-like contexts or when interacting with malicious web content.

Technical details

The vulnerability is characterized by incorrect boundary conditions (CWE-119) and out-of-bounds writes (CWE-787) within the WebRTC component of Mozilla products. An attacker can exploit this flaw over the network without requiring special privileges or user interaction, according to the CISA-ADP CVSS vector. The root cause is a failure to properly restrict operations within the bounds of a memory buffer during WebRTC processing. Successful exploitation could lead to memory corruption, information disclosure, or potentially arbitrary code execution. Patches are available in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Affected products

  • Mozilla Firefox < 150
  • Mozilla Firefox ESR < 140.10
  • Mozilla Thunderbird < 150
  • Mozilla Thunderbird ESR < 140.10
  • Red Hat Enterprise Linux Server (v. 7 ELS) 7 ELS

Timeline

  • 2026-04-21: advisory: Mozilla Foundation Security Advisory published
  • 2026-04-21: patched: Fixed in Firefox 150 and Thunderbird 150

References

Related threats