Description
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Published: 2026-04-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The IP Protection component in Mozilla Firefox and Thunderbird fails to protect sensitive data, resulting in information disclosure. The weakness aligns with CWE-200 and CWE-201, where data is exposed to unauthorized parties. This allows an attacker to obtain data that should remain private, potentially compromising user confidentiality.

Affected Systems

Mozilla Firefox and Thunderbird versions prior to 150 are affected. No specific earlier patch versions are identified, so all releases before 150 may be vulnerable.

Risk and Exploitability

The CVSS score for this issue is 7.5, indicating high severity. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed active exploitation at this time. Attackers would need to engage the IP Protection component, likely through user interaction with a malicious resource or initiating a local action, but the exact vector is not explicit. Given the high CVSS and potential for sensitive data exposure, the risk should be considered significant for exposed systems.

Generated by OpenCVE AI on April 22, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Mozilla Firefox to version 150 or later, which contains the fix for the IP Protection component.
  • Update Mozilla Thunderbird to version 150 or later for the same fix.
  • If an immediate upgrade is not possible, disable or restrict the IP Protection component to prevent data leakage.
  • Stay informed on Mozilla security advisories for updates.

Generated by OpenCVE AI on April 22, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150. Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Description Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150.
Title Information disclosure in the IP Protection component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-27T17:03:18.300Z

Reserved: 2026-04-21T12:41:11.541Z

Link: CVE-2026-6782

cve-icon Vulnrichment

Updated: 2026-04-21T17:56:17.416Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-21T13:16:23.847

Modified: 2026-04-22T15:18:14.977

Link: CVE-2026-6782

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-21T12:41:11Z

Links: CVE-2026-6782 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T15:15:16Z

Weaknesses