CVE-2026-6764 is a boundary condition vulnerability in the DOM Device Interfaces component affecting Mozilla Firefox and Thunderbird applications. The flaw was addressed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. This vulnerability allows improper handling of memory boundaries within the DOM layer, potentially leading to integrity and availability issues. The vulnerability carries a CVSS score of 6.5 (Medium severity) with a network-based attack vector requiring no authentication or user interaction, making it relatively straightforward to exploit remotely. However, impact is limited to integrity and availability concerns, with no confidentiality impact. The EPSS score of 0.00044 indicates this vulnerability ranks higher in exploitability than the vast majority of CVEs, though real-world exploitation remains minimal. There is currently no evidence of active exploitation in the wild, and the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog. Community attention appears limited, as indicated by its inactive status on threat tracking lists. Organizations should prioritize patching to the fixed versions, particularly for systems requiring high availability or integrity assurance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
>= 140.0, < 140.10.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.