Executive brief
Mozilla Firefox and Thunderbird are popular applications used for web browsing and email communication. Multiple memory safety vulnerabilities were identified that could allow an attacker to potentially execute malicious code on a user's system if they visit a compromised website or interact with malicious content. While Thunderbird is less susceptible during standard email reading, both applications should be updated immediately to prevent potential system compromise or data theft.
Technical details
This advisory covers a collection of memory safety bugs (CVE-2026-6784) identified through internal fuzzing and developer reports. The vulnerabilities include various memory corruption issues that, while not individually detailed, are presumed to be exploitable for arbitrary code execution given sufficient effort. The attack vector is remote, typically requiring a user to navigate to a malicious webpage (User Interaction) or operate the software in a browser-like context. In Thunderbird, the risk is mitigated during standard email viewing as scripting is disabled by default, but remains a threat in other contexts. The issues were addressed by improving memory handling and safety checks in the affected components.
Affected products
- Mozilla Firefox 149
- Mozilla Thunderbird 149
Timeline
- 2026-04-21: advisory: Mozilla Foundation Security Advisory MFSA2026-30 and MFSA2026-33 published.
- 2026-04-21: patched: Fixed in Firefox 150 and Thunderbird 150.
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1536243%2C1745382%2C1851073%2C1893400%2C1963301%2C2001319%2C2002899%2C2012436%2C2014435%2C2016901%2C2019916%2C2020486%2C2020612%2C2020817%2C2021788%2C2022051%2C2022367%2C2022431%2C2023302%2C2023670%2C2024225%2C2024238%2C2024240%2C2024265%2C2024367%2C2024369%2C2024424%2C2024760%2C2025281%2C2025361%2C2025387%2C2025466%2C2025954%2C2025958%2C2026278%2C2026292%2C2026297%2C2026378%2C2027148%2C2027287%2C2027341%2C2027384%2C2027427%2C2027694%2C2027993%2C2028009%2C2028270%2C2028416%2C2028524%2C2029295%2C2029699%2C2029800%2C2029801
- https://www.mozilla.org/security/advisories/mfsa2026-30/
- https://www.mozilla.org/security/advisories/mfsa2026-33/
- https://access.redhat.com/security/cve/CVE-2026-6784
- https://bugzilla.redhat.com/show_bug.cgi?id=2460084
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6784.json