CVE-2026-6749 is an information disclosure vulnerability in the Graphics Canvas2D component of Mozilla Firefox and Thunderbird caused by uninitialized memory, potentially allowing attackers to access sensitive data. The vulnerability affects Firefox versions prior to 150, Firefox ESR versions prior to 115.35 and 140.10, and Thunderbird versions prior to 150 and 140.10. The flaw was patched across all supported product lines in coordinated security updates. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, reflecting a network-based attack vector requiring no privileges or user interaction. The attack complexity is low, indicating ease of exploitation, though the impact is limited to confidentiality with no integrity or availability concerns. The moderate FAUCET Risk Score of 47.0 suggests moderate organizational concern, though EPSS scoring indicates minimal real-world prevalence. There is currently no evidence of active exploitation in the wild, with no public exploit code availability and the vulnerability remaining inactive on known exploit lists. The low EPSS score and absence from the Known Exploited Vulnerabilities catalog suggest this vulnerability has not gained significant community or attacker attention. Organizations should prioritize patching based on standard update cycles rather than emergency response protocols.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 115.35.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
>= 140.0, < 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.