CVE-2026-6775 is a boundary condition vulnerability in the WebRTC component affecting Mozilla Firefox and Thunderbird, with fixes deployed in version 150 of both products. The flaw stems from improper handling of memory boundaries within WebRTC functionality, which could allow unauthorized access to sensitive information. This vulnerability carries a CVSS 3.1 score of 5.3 (Medium), with a network-based attack vector requiring no authentication or user interaction, making it relatively straightforward to exploit remotely. The potential impact is limited to confidentiality breaches with no effect on integrity or availability. There is currently no evidence of active exploitation in the wild, with an extremely low EPSS score of 0.00029 indicating minimal likelihood of weaponization, and the vulnerability remains inactive on exploit tracking lists with no publicly available proof-of-concept code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.