Description
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Published: 2026-04-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability consists of several memory safety bugs that appear in multiple Mozilla browser and email client releases. The bugs produce memory corruption and, with sufficient effort, could allow an attacker to execute arbitrary code. They are categorized as out‑of‑bounds read (CWE‑125), use‑after‑free (CWE‑416), and out‑of‑bounds write (CWE‑787). The bugs were fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Affected Systems

Affected products include Mozilla Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149, and Thunderbird 149. The bugs were fixed in Firefox 150, Firefox ESR 115.35, and Firefox ESR 140.10, as well as Thunderbird 150.

Risk and Exploitability

The CVSS score of 8.1 indicates a high‑severity issue that could enable remote code execution; the EPSS score is not available, so the current exploitation probability is uncertain. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits yet. Based on the memory corruption nature, the likely attack vector is remote via malicious web page or email content, although local exploitation is theoretically possible with additional conditions. Successful exploitation would allow an attacker to bypass process integrity and run code with the privileges of the affected user or process.

Generated by OpenCVE AI on April 22, 2026 at 05:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Firefox ESR 115.35, Firefox ESR 140.10, or Firefox 150 (and Thunderbird 150) to apply the patch.
  • Upgrade Thunderbird to version 150 or newer to address the same memory safety bugs.
  • Ensure regular updates from Mozilla’s update channels to receive future security fixes promptly.

Generated by OpenCVE AI on April 22, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6225-1 firefox-esr security update
References
Link Providers
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1935995%2C1999158%2C2015952%2C2021909%2C2022026%2C2022041%2C2022088%2C2022276%2C2022335%2C2022338%2C2022373%2C2022597%2C2022874%2C2023276%2C2023544%2C2023551%2C2023599%2C2023608%2C2023814%2C2024233%2C2024239%2C2024241%2C2024242%2C2024250%2C2024251%2C2024343%2C2024422%2C2024425%2C2024440%2C2024442%2C2024446%2C2024458%2C2024463%2C2024478%2C2024650%2C2024653%2C2024654%2C2024655%2C2024656%2C2024661%2C2024662%2C2024668%2C2024919%2C2025278%2C2025349%2C2025350%2C2025354%2C2025360%2C2025363%2C2025370%2C2025379%2C2025381%2C2025399%2C2025400%2C2025403%2C2025407%2C2025415%2C2025420%2C2025427%2C2025429%2C2025430%2C2025479%2C2025489%2C2025493%2C2025497%2C2025502%2C2025515%2C2025517%2C2025526%2C2025609%2C2025948%2C2025949%2C2025951%2C2025953%2C2025955%2C2025962%2C2025969%2C2025970%2C2025971%2C2025973%2C2025976%2C2025977%2C2026280%2C2026285%2C2026293%2C2026296%2C2026310%2C2027237%2C2027260%2C2027268%2C2027277%2C2027284%2C2027291%2C2027293%2C2027298%2C2027330%2C2027342%2C2027345%2C2027359%2C2027365%2C2027378%2C2027754%2C2027959%2C2027962%2C2027964%2C2027971%2C2027974%2C2027979%2C2027982%2C2027995%2C2028001%2C2028267%2C2028268%2C2028275%2C2028288%2C2028290%2C2028291%2C2028528%2C2028551%2C2028627%2C2028879%2C2028889%2C2029061%2C2029071%2C2029283%2C2029296%2C2029314%2C2029323%2C2029411%2C2029423%2C2029424%2C2029425%2C2029427%2C2029436%2C2029440%2C2029449%2C2029450%2C2029458%2C2029462%2C2029468%2C2029472%2C2029690%2C2029707%2C2029708%2C2029728%2C2029802%2C2029896%2C2029906%2C2030106%2C2030118%2C2030123%2C2030135%2C2030230%2C2030320 cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-6785 cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-6785 cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-30/ cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-31/ cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-31/#CVE-2026-6785 cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-32/ cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-32/#CVE-2026-6785 cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-33/ cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-34/ cve-icon
History

Wed, 22 Apr 2026 12:15:00 +0000


Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, and Firefox ESR 140.10. Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
References

Tue, 21 Apr 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-416
CWE-787
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Description Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, and Firefox ESR 140.10.
Title Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-22T03:56:14.605Z

Reserved: 2026-04-21T12:41:13.671Z

Link: CVE-2026-6785

cve-icon Vulnrichment

Updated: 2026-04-21T13:36:27.240Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-21T12:41:13Z

Links: CVE-2026-6785 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T05:45:09Z

Weaknesses