Junglewise Threat Intelligence

CVE-2026-6754: Mozilla Firefox and Thunderbird use-after-free in JavaScript Engine

CVE-2026-6754 · Severity: high · CVSS 7.5 · Published 2026-04-21

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla has released security updates for Firefox and Thunderbird to address a high-severity vulnerability in the JavaScript engine. This component is responsible for running scripts on websites and within emails. An exploit could allow an attacker to cause the application to crash or potentially execute unauthorized actions, impacting the stability and security of the user's system.

Technical details

A use-after-free vulnerability exists in the JavaScript Engine component of Mozilla Firefox and Thunderbird. The flaw occurs when the engine attempts to access memory that has already been deallocated, often due to improper state management during script execution. An attacker can exploit this by enticing a user to visit a specially crafted webpage or open a malicious email, potentially leading to a denial-of-service (crash) or arbitrary code execution within the context of the application. The vulnerability is tracked as CVE-2026-6754 and has been patched in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Affected products

  • Mozilla Firefox < 150
  • Mozilla Firefox ESR < 115.35, < 140.10
  • Mozilla Thunderbird < 150, < 140.10

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: patched
  • 2026-04-21: advisory

References

Related threats