CVE-2026-6747 is a use-after-free vulnerability in the WebRTC component affecting Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. This memory safety flaw allows attackers to exploit freed memory regions, potentially causing application crashes or other undefined behavior. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily exploitable over the internet. The primary impact is availability denial through application crashes, though the attack complexity is low and no special privileges are required. There is currently no evidence of active exploitation in the wild, with no known public exploit code available. The vulnerability remains inactive on threat intelligence hot lists, and its EPSS score of 0.00047 indicates minimal real-world exploitation probability at this time. However, organizations should prioritize patching given the high CVSS rating and ease of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.