Description
Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Published: 2026-04-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

Memory safety bugs in Firefox 149 and Thunderbird 149 were updated in the description to specify that these bugs involve memory corruption, such as use‑after‑free, double‑free and out‑of bounds writes (CWE‑125, CWE‑416, CWE‑787). The wording still indicates that, with sufficient effort, an attacker could trigger arbitrary code execution, thereby compromising confidentiality, integrity, and availability of the affected system. The likely attack vector remains the processing of external content (web pages, downloads or email), consistent with the original entry, though the exact attack path is not detailed in the CVE.

Affected Systems

Mozilla’s Firefox version 149 is affected. The vulnerability was addressed in Firefox 150, which is the earliest safe release. No detailed patch version data was provided beyond this milestone. If Thunderbird users are affected, the corresponding fix is also in version 150, and Thunderbird is included in the official CNA vendor/product list.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level. EPSS data is not available, so the precise exploitation probability cannot be quantified, but the non‑listing in CISA’s KEV catalog suggests that no active exploitation has been reported yet. Nonetheless, the combination of memory corruption weaknesses and the browser’s privileged execution context poses a significant risk if the vulnerability is exploited.

Generated by OpenCVE AI on April 22, 2026 at 06:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 150 or later, ensuring the update includes the memory‑corruption fixes.
  • If you use Thunderbird, upgrade it to version 150 or later for the same protection.
  • Enable automatic updates for Firefox so that security patches are applied promptly.
  • If an upgrade is not immediately possible, run the browser in a sandboxed environment to limit the impact of potential exploits.

Generated by OpenCVE AI on April 22, 2026 at 06:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 16:30:00 +0000


Thu, 07 May 2026 15:30:00 +0000


Wed, 29 Apr 2026 06:00:00 +0000


Wed, 22 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150. Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
References

Tue, 21 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-416
CWE-787
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 13:15:00 +0000


Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-07T15:12:53.213Z

Reserved: 2026-04-21T12:41:12.823Z

Link: CVE-2026-6784

cve-icon Vulnrichment

Updated: 2026-04-21T13:37:34.528Z

cve-icon NVD

Status : Modified

Published: 2026-04-21T13:16:24.020

Modified: 2026-05-07T16:16:22.957

Link: CVE-2026-6784

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-21T12:41:13Z

Links: CVE-2026-6784 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T07:00:12Z

Weaknesses